PT-2009-5005 · Traidnt · Traidnt Up

Qabandi

·

Publicado

2009-07-27

·

Atualizado

2017-09-19

·

CVE-2009-2605

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Traidnt Up version 2.0
Description The issue concerns SQL injection vulnerabilities in the adminquery.php file. Remote attackers can execute arbitrary SQL commands by manipulating the trupuser and truppassword cookies to access the uploadcp/index.php endpoint.
Recommendations For Traidnt Up version 2.0, consider restricting access to the adminquery.php file and the uploadcp/index.php endpoint until a fix is available. As a temporary workaround, avoid using the trupuser and truppassword cookies in the affected endpoint to minimize the risk of exploitation.

Exploit

Correção

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2605

Produtos afetados

Traidnt Up