PT-2006-4652 · Ufo2000 · Ufo2000
Luigi Auriemma
·
Publicado
2006-07-21
·
Atualizado
2018-10-17
·
CVE-2006-3792
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
UFO2000 version prior to svn 1058
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved through unspecified vectors involving the
packet.c str function in the ServerClientUfo::recv packet function in server protocol.cpp.Recommendations
For UFO2000 version prior to svn 1058, update to a version that includes the fix for this issue to prevent the execution of arbitrary SQL commands.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ufo2000