PT-2006-4201 · Project Eros · Project Eros Bbsengine
Publicado
2006-06-29
·
Atualizado
2017-07-20
·
CVE-2006-3307
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Project EROS bbsengine versions prior to bbsengine-20060429-1550-jam
Description
The issue concerns SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands. This is possible via unspecified parameters in the
php/comment.php and the getpartialmatches method in php/aolbonics.php.Recommendations
For versions prior to bbsengine-20060429-1550-jam, update to a version that includes the necessary security patches to mitigate the SQL injection risk. As a temporary workaround, consider restricting access to the
php/comment.php and php/aolbonics.php files until a patch is available. Avoid using unspecified parameters in these files to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Project Eros Bbsengine