PT-2007-6931 · Toko Instan · Toko Instan

K1Tk4T

·

Publicado

2007-11-15

·

Atualizado

2017-09-29

·

CVE-2007-6004

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Toko Instan version 7.6
Description The issue concerns SQL injection vulnerabilities in the index.php file. These vulnerabilities allow remote attackers to execute arbitrary SQL commands. This can be achieved via two parameters: the id parameter in an 'artikel' action or the katid parameter in a 'produk' action.
Recommendations For Toko Instan version 7.6, consider restricting access to the id and katid parameters in the 'artikel' and 'produk' actions, respectively, until a patch is available. As a temporary workaround, avoid using these parameters in the affected API endpoint.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6004

Produtos afetados

Toko Instan