PT-2005-4623 · Softbiz · Softbiz Resource Repository Script
Publicado
2005-11-29
·
Atualizado
2017-07-20
·
CVE-2005-3879
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Softbiz Resource Repository Script versions 1.1 and earlier
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
sbres id parameter in files such as "details res.php", "refer friend.php", and "report link.php", and the sbcat id parameter in "showcats.php".Recommendations
For Softbiz Resource Repository Script versions 1.1 and earlier, consider restricting access to the vulnerable parameters
sbres id and sbcat id until a fix is available. As a temporary workaround, avoid using these parameters in the affected files.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Softbiz Resource Repository Script