PT-2008-5460 · Assetman · Assetman

Neo Anderson

+1

·

Publicado

2008-09-22

·

Atualizado

2017-09-29

·

CVE-2008-4161

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Assetman version 2.5b
Description The issue allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks. This is achieved through a combination of crafted order and order by parameters in a "search all" action.
Recommendations For Assetman version 2.5b, consider restricting access to the search inv.php file until a patch is available, and avoid using the order and order by parameters in the search all action to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-4161

Produtos afetados

Assetman