PT-2006-5137 · Cloudnine · Cloudnine Interactive Links Manager

Aliaksandr Hartsuyeu

·

Publicado

2006-08-24

·

Atualizado

2018-10-17

·

CVE-2006-4328

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CloudNine Interactive Links Manager version 2006-06-12
Description The issue allows remote attackers to execute arbitrary SQL commands. This is possible when the magic quotes gpc setting is disabled. The nick parameter is vulnerable to SQL injection.
Recommendations For CloudNine Interactive Links Manager version 2006-06-12, consider disabling the nick parameter in the admin.php file until a patch is available. Additionally, enabling magic quotes gpc can help mitigate this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4328

Produtos afetados

Cloudnine Interactive Links Manager