Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Jafer Al Zidjali

#40036de 53,635
6.8CVSS total
Vulnerabilidades · 1
PT-2009-5628
6.8
2009-09-23
Saphplesson · Saphplesson · CVE-2009-3321
**Name of the Vulnerable Software and Affected Versions** SaphpLesson version 4.3 **Description** The issue allows remote attackers to execute arbitrary SQL commands when the `magic quotes gpc` setting is disabled. This can be achieved via the `CLIENT IP` HTTP header. **Recommendations** For SaphpLesson version 4.3, consider enabling the `magic quotes gpc` setting to prevent SQL injection attacks. Additionally, as a temporary workaround, restrict access to the SQL database to minimize the risk of exploitation.