PT-2006-1443 · Insane Visions · Insane Visions Blogphp

Imei

·

Publicado

2006-01-22

·

Atualizado

2018-10-19

·

CVE-2006-0372

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Insane Visions BlogPHP version 1.0
Description The issue concerns SQL injection vulnerabilities in the config.php file. Remote attackers can execute arbitrary SQL commands by manipulating the blogphp username or blogphp password parameter in a cookie.
Recommendations For Insane Visions BlogPHP version 1.0, consider restricting access to the config.php file and validating user input to prevent SQL injection attacks. As a temporary workaround, avoid using the blogphp username and blogphp password parameters in cookies until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0372

Produtos afetados

Insane Visions Blogphp