PT-2009-1640 · Cspartner · Cspartner

Staker

·

Publicado

2009-02-19

·

Atualizado

2017-09-29

·

CVE-2008-6165

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CSPartner version 0.1
Description The issue allows remote attackers to execute arbitrary SQL commands. This is possible via the pseudo and passe parameters in the gestion.php file when magic quotes gpc is disabled.
Recommendations For CSPartner version 0.1, consider disabling the magic quotes gpc option or restricting access to the gestion.php file until a patch is available. As a temporary workaround, avoid using the pseudo and passe parameters in the affected API endpoint until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6165

Produtos afetados

Cspartner