PT-2006-2337 · Unknown · Skull-Splitter Php Downloadcounter For Wallpapers

Aliaksandr Hartsuyeu

·

Publicado

2006-03-21

·

Atualizado

2018-10-18

·

CVE-2006-1328

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Skull-Splitter PHP Downloadcounter for Wallpapers version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the count fieldname, url fieldname, or url parameters.
Recommendations For Skull-Splitter PHP Downloadcounter for Wallpapers version 1.0, consider restricting access to the count.php file until a patch is available. As a temporary workaround, avoid using the count fieldname, url fieldname, and url parameters in the affected API endpoint.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1328

Produtos afetados

Skull-Splitter Php Downloadcounter For Wallpapers