PT-2005-4022 · Aenovo · Aenovo+2
Devil_Box
+2
·
Publicado
2005-10-14
·
Atualizado
2017-07-11
·
CVE-2005-3208
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
aeNovo (affected versions not specified)
aeNovoShop (affected versions not specified)
aeNovoWYSI (affected versions not specified)
Description
The issue allows remote attackers to execute arbitrary SQL code, potentially enabling cross-site scripting (XSS) attacks in resulting error messages. This can be achieved via the
password parameter in "control.asp" and the strSQL parameter in "search.asp".Recommendations
For aeNovo, consider restricting access to the
control.asp and search.asp pages until a fix is available.
For aeNovoShop, avoid using the password parameter in "control.asp" and the strSQL parameter in "search.asp" until the issue is resolved.
For aeNovoWYSI, as a temporary workaround, consider disabling the execution of SQL code from user-input parameters in "control.asp" and "search.asp" until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Aenovo
Aenovoshop
Aenovowysi