PT-2007-1313 · Unknown · Super Link Exchange Script

Luny

·

Publicado

2007-02-23

·

Atualizado

2018-10-16

·

CVE-2006-7034

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Super Link Exchange Script version 1.0
Description The issue allows remote attackers to execute arbitrary SQL queries. This is achieved via the cat parameter in the directory.php file.
Recommendations For Super Link Exchange Script version 1.0, consider restricting access to the directory.php file until a patch is available. As a temporary workaround, avoid using the cat parameter in the affected directory.php file to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-7034

Produtos afetados

Super Link Exchange Script