PT-2001-1463 · Newsdaemon · Newsdaemon
Publicado
2001-05-03
·
Atualizado
2017-10-10
·
CVE-2001-0234
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NewsDaemon versions prior to 0.21b
Description
The issue allows remote attackers to execute arbitrary SQL queries and gain privileges. This is achieved by exploiting a malformed
user username parameter.Recommendations
For versions prior to 0.21b, update to version 0.21b or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable parameter
user username to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Newsdaemon