PT-2005-2894 · Loki · Loki Download Manager
Salmanooh
·
Publicado
2005-06-08
·
Atualizado
2016-10-18
·
CVE-2005-1943
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Loki download manager version 2.0
Description
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the
password field to the "default.asp" endpoint or the cat parameter to the "catinfo.asp" endpoint.Recommendations
For Loki download manager version 2.0, consider restricting access to the "default.asp" and "catinfo.asp" endpoints until a patch is available. As a temporary workaround, avoid using the
password field in the "default.asp" endpoint and the cat parameter in the "catinfo.asp" endpoint to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Loki Download Manager