PT-2008-1911 · Osticket · Eticket

L4Teral

·

Publicado

2008-01-15

·

Atualizado

2018-10-15

·

CVE-2008-0267

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions eTicket version 1.5.5.2
Description The issue allows remote authenticated users to execute arbitrary SQL commands via the status, sort, and way parameters to "search.php", and remote authenticated administrators to execute arbitrary SQL commands via the msg and password parameters to "admin.php".
Recommendations For version 1.5.5.2, consider restricting access to the "search.php" and "admin.php" files until a patch is available, and avoid using the status, sort, way, msg, and password parameters in these files to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-0267

Produtos afetados

Eticket