PT-2007-2828 · Grayscale · Grayscale Blog

Omnipresent

·

Publicado

2007-03-13

·

Atualizado

2018-10-16

·

CVE-2007-1434

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Grayscale Blog versions 0.8.0 and earlier
Description A SQL injection issue might allow remote attackers to execute arbitrary SQL commands. This is possible via the id parameter to "userdetail.php", the url parameter to "jump.php", and the id variable to "detail.php".
Recommendations For Grayscale Blog versions 0.8.0 and earlier, avoid using the id parameter in "userdetail.php" and the id variable in "detail.php", and restrict the url parameter in "jump.php" until a fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1434

Produtos afetados

Grayscale Blog