PT-2005-4620 · Ad Center · Ad Center Adc2000 Ng Pro

Publicado

2005-11-29

·

Atualizado

2011-03-08

·

CVE-2005-3876

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AD Center ADC2000 NG Pro versions 1.2
Description The issue concerns SQL injection vulnerabilities in the adcbrowres.php file. Remote attackers can execute arbitrary SQL commands by manipulating the cat and lang parameters.
Recommendations For AD Center ADC2000 NG Pro version 1.2, as a temporary workaround, consider restricting access to the adcbrowres.php file until a patch is available. Avoid using the cat and lang parameters in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3876

Produtos afetados

Ad Center Adc2000 Ng Pro