PT-2006-2161 · Cyboards · Cyboards Php Lite
Aliaksandr Hartsuyeu
·
Publicado
2006-03-10
·
Atualizado
2018-10-18
·
CVE-2006-1134
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CyBoards PHP Lite version 1.25
Description
The issue allows remote attackers to execute arbitrary SQL commands when the
magic quotes gpc setting is disabled. This can be achieved by manipulating the parent parameter in the "post.php" and possibly "process post.php" API endpoints.Recommendations
For CyBoards PHP Lite version 1.25, consider disabling the
parent parameter in the affected API endpoints until a patch is available. Restrict access to the "post.php" and "process post.php" endpoints to minimize the risk of exploitation. Enable the magic quotes gpc setting as a temporary workaround to mitigate the risk.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cyboards Php Lite