PT-2009-4768 · W3B · W3B|Cms Gaestebuch Guestbook Module

Dnx

·

Publicado

2009-07-07

·

Atualizado

2017-09-19

·

CVE-2009-2337

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions w3b|cms Gaestebuch Guestbook Module version 3.0.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is possible due to a SQL injection vulnerability when the magic quotes gpc setting is disabled. The vulnerability can be exploited via the spam id parameter.
Recommendations For version 3.0.0, consider disabling the includes/module/book/index.inc.php module until a patch is available, or restrict access to it to minimize the risk of exploitation. Avoid using the spam id parameter in the affected module until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2337

Produtos afetados

W3B|Cms Gaestebuch Guestbook Module