PT-2007-4134 · Alstrasoft · Alstrasoft E-Friends
Blackhawk
·
Publicado
2007-05-22
·
Atualizado
2017-10-11
·
CVE-2007-2824
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AlstraSoft E-Friends versions 4.21 and earlier
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
pack parameter in a "paypal" action for "index.php".Recommendations
For versions 4.21 and earlier, consider restricting access to the "paypal" action in "index.php" to minimize the risk of exploitation until a patch is available. Avoid using the
pack parameter in the affected API endpoint until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alstrasoft E-Friends