PT-2009-2078 · Develop It Easy · Developiteasy Events Calendar

Cyb3R-1St

·

Publicado

2009-04-06

·

Atualizado

2017-09-29

·

CVE-2008-6608

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DevelopItEasy Events Calendar version 1.2
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the "user name" parameter to "admin/index.php", the "user pass" parameter to "admin/index.php", or the id parameter to "calendar details.php".
Recommendations For DevelopItEasy Events Calendar version 1.2, consider restricting access to the vulnerable parameters user name and user pass in the "admin/index.php" endpoint, as well as the id parameter in the "calendar details.php" endpoint, until a fix is available.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6608

Produtos afetados

Developiteasy Events Calendar