PT-2006-7064 · Dudirectory · Directory-Pro+2

Meftun

·

Publicado

2006-12-10

·

Atualizado

2018-10-17

·

CVE-2006-6455

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DUdirectory version 3.1 DUdirectory Pro versions 3.x DUdirectory Pro SQL versions 3.x
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved by exploiting the Username or Password parameter in the admin/default.asp file.
Recommendations For DUdirectory version 3.1, update the admin/default.asp file to properly sanitize the Username and Password parameters. For DUdirectory Pro versions 3.x, restrict access to the admin/default.asp file until a patch is available to fix the SQL injection issue. For DUdirectory Pro SQL versions 3.x, consider disabling the Username and Password parameters in the admin/default.asp file as a temporary workaround until a fix is released.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6455

Produtos afetados

Dudirectory
Directory-Pro
Dudirectory Pro Sql