PT-2007-4886 · Gamesitescript · Gamesitescript
Xenduer77
·
Publicado
2007-07-10
·
Atualizado
2017-09-29
·
CVE-2007-3631
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GameSiteScript (gss) versions 3.1 and earlier
Description
The issue is related to a SQL injection vulnerability in the index.php file. This vulnerability allows remote attackers to execute arbitrary SQL commands via the
params parameter, specifically due to missing input validation of the id field.Recommendations
For GameSiteScript (gss) versions 3.1 and earlier, consider validating user input for the
id field in the params parameter to prevent SQL injection attacks. As a temporary workaround, restrict access to the index.php file until a proper fix is applied.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Gamesitescript