PT-2006-4030 · Cms Mundo · Cms Mundo

Andreas Sandblad

·

Publicado

2006-07-13

·

Atualizado

2017-07-20

·

CVE-2006-3135

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CMS Mundo version 1.0 build 008
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via several parameters and fields, including the news id parameter in the news module, searchstring parameter in the search module, id parameter in the webshop module, username parameter in index.php, and various fields during a user profile update, such as Name, Address, Zip, City, Country, and Email.
Recommendations For CMS Mundo version 1.0 build 008, consider restricting access to the news, search, and webshop modules, and limit user profile updates until a fix is available. As a temporary workaround, avoid using the news id, searchstring, id, and username parameters in their respective modules, and be cautious with user input in the Name, Address, Zip, City, Country, and Email fields during user profile updates.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3135

Produtos afetados

Cms Mundo