PT-2006-5611 · Clickblog · Clickblog

Ajann

·

Publicado

2006-09-19

·

Atualizado

2018-10-17

·

CVE-2006-4857

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ClickBlog version 2.0
Description The issue concerns a SQL injection vulnerability in the default.asp login page. This vulnerability allows remote attackers to execute arbitrary SQL commands by manipulating the username and form codeword (also known as the Password field) parameters in the login form.
Recommendations For ClickBlog version 2.0, consider restricting access to the default.asp login page until a fix is available, and avoid using the username and form codeword parameters in a way that could facilitate SQL injection attacks.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4857

Produtos afetados

Clickblog