PT-2010-2809 · 1024 · 1024 Cms

Publicado

2010-03-24

·

Atualizado

2010-12-14

·

CVE-2010-1093

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions 1024 CMS version 2.1.1
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is possible when the magic quotes gpc setting is disabled. The issue can be exploited via the id parameter in a vp action.
Recommendations For 1024 CMS version 2.1.1, consider disabling the vp action or restricting access to the rss.php file until a patch is available. Additionally, enabling magic quotes gpc can help mitigate this issue.

Exploit

Correção

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1093

Produtos afetados

1024 Cms