PT-2010-1359 · Sqlite · Sqlitemanager

Publicado

2010-01-04

·

Atualizado

2018-10-10

·

CVE-2009-4539

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SQLiteManager version 1.2.0
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the redirect parameter in the main.php file.
Recommendations For SQLiteManager version 1.2.0, avoid using the redirect parameter in the main.php file until a patch is available. As a temporary workaround, consider restricting access to the main.php file to minimize the risk of exploitation.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4539

Produtos afetados

Sqlitemanager