PT-2002-2601 · Lokwabb · Lokwabb

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-1879

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LokwaBB version 1.2.2
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the member parameter to "member.php" or the loser parameter to "misc.php".
Recommendations For LokwaBB version 1.2.2, consider restricting access to the "member.php" and "misc.php" scripts until a patch is available. As a temporary workaround, avoid using the member and loser parameters in the affected API endpoints.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-1879

Produtos afetados

Lokwabb