PT-2010-2809 · 1024 · 1024 Cms
Publicado
2010-03-24
·
Atualizado
2010-12-14
·
CVE-2010-1093
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
1024 CMS version 2.1.1
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is possible when the
magic quotes gpc setting is disabled. The issue can be exploited via the id parameter in a vp action.Recommendations
For 1024 CMS version 2.1.1, consider disabling the
vp action or restricting access to the rss.php file until a patch is available. Additionally, enabling magic quotes gpc can help mitigate this issue.Exploit
Correção
RCE
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
1024 Cms