Cms Buzz · Cms Buzz · CVE-2008-4374
Name of the Vulnerable Software and Affected Versions:
CMS Buzz (affected versions not specified)
Description:
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved by manipulating the `id` parameter in a "playgame" action within the index.php file.
Recommendations:
For CMS Buzz, consider restricting access to the index.php file or the "playgame" action until a patch is available. As a temporary workaround, avoid using the `id` parameter in the affected action to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.