PT-2007-5321 · Berthanas · Berthanas Ziyaretci Defteri

Publicado

2007-08-01

·

Atualizado

2018-10-15

·

CVE-2007-4119

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Berthanas Ziyaretci Defteri version 2.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved through SQL injection vulnerabilities in the yonetici.asp file, specifically via the user and Pass fields.
Recommendations For Berthanas Ziyaretci Defteri version 2.0, consider restricting access to the yonetici.asp file until a patch is available, and avoid using the user and Pass fields in a manner that could facilitate SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-4119

Produtos afetados

Berthanas Ziyaretci Defteri