Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Vyc0D

#37220de 53,632
7.5CVSS total
Vulnerabilidades · 1
PT-2010-4831
7.5
2010-09-17
Endonesia · Endonesia · CVE-2010-3461
**Name of the Vulnerable Software and Affected Versions** eNdonesia version 8.4 **Description** A SQL injection issue exists in the Publisher module, allowing remote attackers to execute arbitrary SQL commands. This is achieved via the `artid` parameter in a `printarticle` action to `mod.php`. **Recommendations** For eNdonesia version 8.4, avoid using the `artid` parameter in the `printarticle` action to `mod.php` until a fix is available. As a temporary workaround, consider restricting access to the Publisher module to minimize the risk of exploitation.