PT-2006-5523 · F Art · F-Art Blog:Cms

Omid

·

Publicado

2006-09-13

·

Atualizado

2018-10-17

·

CVE-2006-4748

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions F-ART BLOG:CMS version 4.1
Description The issue allows remote attackers to execute arbitrary SQL commands via the xagent, xpath, xreferer, and xdns parameters in admin/plugins/NP Log.php, and the pitem parameter in admin/plugins/NP Poll.php. Additionally, remote authenticated users can execute arbitrary SQL commands via the pageRef parameter in admin/plugins/NP Referrer.php.
Recommendations For F-ART BLOG:CMS version 4.1, consider disabling the NP Log.php, NP Poll.php, and NP Referrer.php plugins until a patch is available. Restrict access to the xagent, xpath, xreferer, xdns, pitem, and pageRef parameters to minimize the risk of exploitation. Avoid using these parameters in the affected API endpoints until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4748

Produtos afetados

F-Art Blog:Cms