PT-2011-1758 · 6Kbbs · 6Kbbs

Zym

·

Publicado

2011-07-08

·

Atualizado

2017-08-29

·

CVE-2010-4812

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions 6kbbs version 8.0 build 20100901
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the tids[] parameter to "ajaxadmin.php" and the msgids[] parameter to "ajaxmember.php".
Recommendations For version 8.0 build 20100901, consider restricting access to the "ajaxadmin.php" and "ajaxmember.php" API endpoints until a patch is available. As a temporary workaround, avoid using the tids[] and msgids[] parameters in the affected API endpoints.

Correção

RCE

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-4812

Produtos afetados

6Kbbs