PT-2006-1172 · Intouch · Intouch

Aliaksandr Hartsuyeu

·

Publicado

2006-01-05

·

Atualizado

2018-10-19

·

CVE-2006-0088

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: inTouch version 0.5.1 Alpha
Description: The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the user parameter in the intouch.lib.php file.
Recommendations: For inTouch version 0.5.1 Alpha, avoid using the user parameter in the intouch.lib.php file until a fix is available. Consider implementing input validation and sanitization for the user parameter to prevent SQL injection attacks.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0088

Produtos afetados

Intouch