PT-2005-4952 · Php · Php Support Tickets

Publicado

2005-12-15

·

Atualizado

2011-03-08

·

CVE-2005-4264

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP Support Tickets version 2.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is possible via the username and password fields, and the id parameter.
Recommendations For PHP Support Tickets version 2.0, consider validating and sanitizing user input for the username, password, and id parameter to prevent SQL injection attacks. As a temporary workaround, restrict access to the index.php file until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4264

Produtos afetados

Php Support Tickets