PT-2002-1287 · Xoops · Xoops

Publicado

2002-05-03

·

Atualizado

2008-09-11

·

CVE-2002-0216

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions XOOPS version 1.0 RC1
Description The issue allows remote attackers to obtain sensitive information via a SQL injection attack in the uid parameter of the 'userinfo.php' file.
Recommendations For XOOPS version 1.0 RC1, avoid using the uid parameter in the userinfo.php file until the issue is resolved. Consider restricting access to the userinfo.php file to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0216

Produtos afetados

Xoops