PT-2004-2962 · Linpha · Linpha

Fernando Quintero

+1

·

Publicado

2004-07-29

·

Atualizado

2017-07-11

·

CVE-2004-2066

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LinPHA version 0.9.4
Description The issue allows remote attackers to execute arbitrary SQL code and bypass authentication. This is achieved via the linpha userid or linpha password cookies.
Recommendations For LinPHA version 0.9.4, update to a version that fixes the SQL injection issue to prevent remote attackers from executing arbitrary SQL code and bypassing authentication.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-2066

Produtos afetados

Linpha