PT-2006-3668 · Osic · Open Searchable Image Catalogue
Nenad Jovanovic
·
Publicado
2006-06-01
·
Atualizado
2018-10-18
·
CVE-2006-2748
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Open Searchable Image Catalogue (OSIC) versions prior to 0.7.0.1
Description
The issue allows remote attackers to inject arbitrary SQL commands via multiple vectors. This is demonstrated by the
type parameter in "adminfunctions.php" and the catalogue id parameter in "editcatalogue.php".Recommendations
For versions prior to 0.7.0.1, update to version 0.7.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the
do mysql query function in "core.php" until a patch is available. Avoid using the type parameter in "adminfunctions.php" and the catalogue id parameter in "editcatalogue.php" until the issue is resolved.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Open Searchable Image Catalogue