PT-2008-5757 · Adaptcms · Adaptcms Pro+1
Staker
·
Publicado
2008-10-09
·
Atualizado
2022-05-02
·
CVE-2008-4524
CVSS v4.0
8.9
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |
Name of the Vulnerable Software and Affected Versions
AdaptCMS Lite version 1.3
AdaptCMS Pro version 1.3
Description
The issue concerns a SQL injection vulnerability in the "Check User" feature, specifically in the includes/check user.php file. This vulnerability allows remote attackers to execute arbitrary SQL commands by manipulating the
user name parameter.Recommendations
For AdaptCMS Lite version 1.3, avoid using the
user name parameter in the affected "Check User" feature until a patch is available.
For AdaptCMS Pro version 1.3, restrict access to the includes/check user.php file to minimize the risk of exploitation.Exploit
Correção
RCE
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Adaptcms Lite
Adaptcms Pro