PT-2006-4009 · Chipmailer · Chipmailer
Tamriel
·
Publicado
2006-06-21
·
Atualizado
2017-07-20
·
CVE-2006-3111
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Chipmailer version 1.09
Description
The issue allows remote attackers to execute arbitrary SQL commands via multiple parameters in the main.php file. The vulnerable parameters include
anfang, name, mail, anrede, vorname, nachname, gebtag, gebmonat, and gebjahr.Recommendations
For Chipmailer version 1.09, consider restricting access to the main.php file until a patch is available. As a temporary workaround, avoid using the parameters
anfang, name, mail, anrede, vorname, nachname, gebtag, gebmonat, and gebjahr in the affected API endpoint.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Chipmailer