PT-2005-4883 · Scout Portal Toolkit · Scout Portal Toolkit
Joss
·
Publicado
2005-12-13
·
Atualizado
2018-10-19
·
CVE-2005-4195
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Scout Portal Toolkit (SPT) versions 1.3.1 and earlier
Scout Portal Toolkit (SPT) version 1.4.0
Description
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via several parameters in different PHP files, including the
ParentId parameter in "SPT--BrowseResources.php", the ResourceId parameter in "SPT--FullRecord.php", the ResourceOffset parameter in "SPT--Home.php", and the F UserName and F Password parameters in "SPT--UserLogin.php".Recommendations
For Scout Portal Toolkit (SPT) versions 1.3.1 and earlier, consider restricting access to the vulnerable PHP files until a patch is available.
For Scout Portal Toolkit (SPT) version 1.4.0, avoid using the
ParentId parameter in "SPT--BrowseResources.php" until the issue is resolved.
As a temporary workaround, consider disabling the SQL execution functionality in the affected parameters until a patch is available.
Restrict access to the F UserName and F Password parameters in "SPT--UserLogin.php" to minimize the risk of exploitation.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Scout Portal Toolkit