PT-2010-4645 · Unknown · Galeriashqip

Valentin Hoebel

·

Publicado

2010-09-03

·

Atualizado

2017-08-17

·

CVE-2010-3207

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GaleriaSHQIP version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is possible when the magic quotes gpc setting is disabled. The album id parameter is used in the exploitation.
Recommendations For GaleriaSHQIP version 1.0, consider enabling the magic quotes gpc setting to prevent SQL injection attacks. Additionally, restrict access to the "index.php" file until a proper fix is applied, and avoid using the album id parameter in sensitive queries. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-3207

Produtos afetados

Galeriashqip