PT-2007-7249 · Dwdirectory · Dwdirectory

T0Pp8Uzz

+1

·

Publicado

2007-12-17

·

Atualizado

2017-09-29

·

CVE-2007-6392

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DWdirectory versions 2.1 and earlier
Description The issue allows remote attackers to execute arbitrary SQL commands via the search parameter to the "/search" URI. This could potentially lead to unauthorized access or manipulation of database content.
Recommendations For DWdirectory versions 2.1 and earlier, consider restricting access to the "/search" URI or disabling the search parameter until a patch is available. Additionally, limiting database privileges to the minimum required for the application can help minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6392

Produtos afetados

Dwdirectory