PT-2006-4652 · Ufo2000 · Ufo2000

Luigi Auriemma

·

Publicado

2006-07-21

·

Atualizado

2018-10-17

·

CVE-2006-3792

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions UFO2000 version prior to svn 1058
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved through unspecified vectors involving the packet.c str function in the ServerClientUfo::recv packet function in server protocol.cpp.
Recommendations For UFO2000 version prior to svn 1058, update to a version that includes the fix for this issue to prevent the execution of arbitrary SQL commands.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-3792

Produtos afetados

Ufo2000