PT-2007-4886 · Gamesitescript · Gamesitescript

Xenduer77

·

Publicado

2007-07-10

·

Atualizado

2017-09-29

·

CVE-2007-3631

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GameSiteScript (gss) versions 3.1 and earlier
Description The issue is related to a SQL injection vulnerability in the index.php file. This vulnerability allows remote attackers to execute arbitrary SQL commands via the params parameter, specifically due to missing input validation of the id field.
Recommendations For GameSiteScript (gss) versions 3.1 and earlier, consider validating user input for the id field in the params parameter to prevent SQL injection attacks. As a temporary workaround, restrict access to the index.php file until a proper fix is applied.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3631

Produtos afetados

Gamesitescript