PT-2006-4201 · Project Eros · Project Eros Bbsengine

Publicado

2006-06-29

·

Atualizado

2017-07-20

·

CVE-2006-3307

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Project EROS bbsengine versions prior to bbsengine-20060429-1550-jam
Description The issue concerns SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands. This is possible via unspecified parameters in the php/comment.php and the getpartialmatches method in php/aolbonics.php.
Recommendations For versions prior to bbsengine-20060429-1550-jam, update to a version that includes the necessary security patches to mitigate the SQL injection risk. As a temporary workaround, consider restricting access to the php/comment.php and php/aolbonics.php files until a patch is available. Avoid using unspecified parameters in these files to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3307

Produtos afetados

Project Eros Bbsengine