PT-2003-2536 · Teapop+2 · Teapop+2

Publicado

1970-01-01

·

Atualizado

2008-09-10

·

CVE-2003-0515

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions teapop versions 0.3.5 and earlier
Description The issue allows attackers to execute arbitrary SQL and possibly gain privileges due to SQL injection vulnerabilities in the PostgreSQL or MySQL authentication modules. Exploitation of the vulnerabilities can lead to disruption of confidentiality, integrity, and availability of protected information and can be carried out remotely.
Recommendations For teapop versions 0.3.5 and earlier, update to a version later than 0.3.5 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-03494
BDU:2015-03495
BDU:2015-03496
CVE-2003-0515
DSA-347

Produtos afetados

Mysql Server
Postgresql
Teapop