PT-2010-1414 · Php · Php Inventory

Publicado

2010-01-12

·

Atualizado

2010-01-13

·

CVE-2009-4595

CVSS v2.0

6.0

Média

VetorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP Inventory version 1.2
Description The issue allows remote authenticated users to execute arbitrary SQL commands. This is achieved via the sup id parameter in a suppliers details action in the index.php file.
Recommendations For PHP Inventory version 1.2, consider restricting access to the sup id parameter in the suppliers details action until a patch is available. As a temporary workaround, avoid using the sup id parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-4595

Produtos afetados

Php Inventory