PT-2006-2489 · Php · Php Ticket

Undefined1

·

Publicado

2006-03-29

·

Atualizado

2017-10-19

·

CVE-2006-1481

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHP Ticket version 0.71
Description: The issue allows remote authenticated users to execute arbitrary SQL commands and obtain sensitive information, such as usernames and passwords, via the frm search in parameter in the search.php file.
Recommendations: For PHP Ticket version 0.71, consider restricting access to the search.php file or disabling the frm search in parameter to minimize the risk of exploitation until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1481

Produtos afetados

Php Ticket