PT-2004-3216 · Phpwebsite · Phpwebsite

David Sopas Ferreira

·

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-2322

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: phpWebSite versions prior to 0.9.3-2
Description: The issue allows remote attackers to execute arbitrary SQL queries. This can be demonstrated using the ANN id parameter to the announce module.
Recommendations: For versions prior to 0.9.3-2, update to version 0.9.3-2 or later to resolve the issue. As a temporary workaround, consider restricting access to the announce and notes modules until the update is applied. Avoid using the ANN id parameter in the affected modules until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-2322

Produtos afetados

Phpwebsite