PT-2008-3147 · Postnuke · Postnuke

The:Paradox

·

Publicado

2008-03-31

·

Atualizado

2017-09-29

·

CVE-2008-1591

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PostNuke versions 0.764 and earlier
Description The issue allows remote attackers to conduct SQL injection attacks and execute arbitrary SQL commands via input associated with server variables, such as the CLIENT IP HTTP header (HTTP CLIENT IP variable), due to the pnVarPrepForStore function skipping input sanitization when magic quotes runtime is enabled.
Recommendations For PostNuke versions 0.764 and earlier, consider disabling the pnVarPrepForStore function or restricting input associated with server variables until a patch is available. Additionally, disabling magic quotes runtime may help mitigate the risk of SQL injection attacks.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-1591

Produtos afetados

Postnuke