PT-2005-4947 · Aspbb · Aspbb

Publicado

2005-12-15

·

Atualizado

2017-07-20

·

CVE-2005-4259

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ASPBB version 0.4
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the TID parameter in "topic.asp", the FORUM ID parameter in "forum.asp", and the PROFILE ID parameter in "profile.asp".
Recommendations For ASPBB version 0.4, consider restricting access to the vulnerable parameters TID, FORUM ID, and PROFILE ID in the respective API endpoints "topic.asp", "forum.asp", and "profile.asp" until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4259

Produtos afetados

Aspbb