PT-2005-4050 · Cyphor · Cyphor

Rgod

·

Publicado

2005-10-14

·

Atualizado

2017-07-11

·

CVE-2005-3236

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cyphor version 0.19
Description The issue allows remote attackers to execute arbitrary SQL and obtain administrative access. This can be achieved via the fid parameter of "newmsg.php" or the nick parameter of "lostpwd.php". When the SQL syntax is invalid, it can also enable XSS attacks.
Recommendations For Cyphor version 0.19, consider restricting access to the newmsg.php and lostpwd.php scripts until a patch is available. As a temporary workaround, avoid using the fid and nick parameters in these scripts to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3236

Produtos afetados

Cyphor