PT-2005-2384 · Phpcoin · Phpcoin

Diabolic Crab

·

Publicado

2005-05-02

·

Atualizado

2017-07-11

·

CVE-2005-1384

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: phpCoin version 1.2.2
Description: The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via several parameters, including the search parameter to "index.php", the phpcoinsessid parameter to "login.php", and the id, dtopic id, or dcat id parameters to "mod.php".
Recommendations: For phpCoin version 1.2.2, as a temporary workaround, consider restricting access to the vulnerable API endpoints, such as "index.php", "login.php", and "mod.php", until a patch is available. Avoid using the parameters search, phpcoinsessid, id, dtopic id, or dcat id in the affected endpoints until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-1384

Produtos afetados

Phpcoin