PT-2006-6009 · Xeobook · Xeobook

Tamriel

·

Publicado

2006-10-13

·

Atualizado

2018-10-17

·

CVE-2006-5287

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Xeobook version 0.93
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the User-Agent HTTP header or specific parameters, including gb entry text, gb location, gb fullname, and gb sex.
Recommendations For Xeobook version 0.93, consider validating and sanitizing user input for the User-Agent HTTP header and the parameters gb entry text, gb location, gb fullname, and gb sex to prevent SQL injection attacks. As a temporary workaround, restrict access to the sign.php file until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5287

Produtos afetados

Xeobook