Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Coksnuss

#36016de 53,632
7.5CVSS total
Vulnerabilidades · 1
PT-2009-5250
7.5
2009-08-20
Scripteen · Scripteen Free Image Hosting Script · CVE-2009-2892
Name of the Vulnerable Software and Affected Versions: Scripteen Free Image Hosting Script version 2.3 Description: The issue concerns SQL injection vulnerabilities in the header.php file. Remote attackers can execute arbitrary SQL commands by manipulating the `cookid` or `cookgid` cookie. Recommendations: For Scripteen Free Image Hosting Script version 2.3, update the header.php file to properly sanitize and validate user input to prevent SQL injection attacks. As a temporary workaround, consider implementing input validation for the `cookid` and `cookgid` cookies to minimize the risk of exploitation.