PT-2006-1747 · Calimba · Calimba

Aliaksandr Hartsuyeu

·

Publicado

2006-02-15

·

Atualizado

2018-10-19

·

CVE-2006-0693

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CALimba versions 0.99.2 beta and earlier
Description The issue allows remote attackers to execute arbitrary SQL commands and bypass login authentication. This is achieved via the login and password parameters in the rb auth.php file.
Recommendations For versions 0.99.2 beta and earlier, update to a version that fixes the SQL injection vulnerabilities in the rb auth.php file to prevent remote attackers from executing arbitrary SQL commands and bypassing login authentication.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0693

Produtos afetados

Calimba