PT-2009-5004 · Zen · Zen Help Desk

Tiger-Dz

·

Publicado

2009-07-27

·

Atualizado

2017-09-19

·

CVE-2009-2604

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zen Help Desk version 2.1
Description The issue concerns SQL injection vulnerabilities in the adminlogin.asp file. Remote attackers can execute arbitrary SQL commands by manipulating the userid (also known as username) and PassWord parameters in the admin.asp file.
Recommendations For Zen Help Desk version 2.1, consider restricting access to the adminlogin.asp file and avoid using the userid and PassWord parameters in the admin.asp file until a fix is available. As a temporary workaround, restrict the input for these parameters to minimize the risk of SQL injection attacks.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2604

Produtos afetados

Zen Help Desk