PT-2011-5045 · Pixie · Pixie Cms
Piranha
·
Publicado
2011-12-08
·
Atualizado
2021-03-29
·
CVE-2011-4710
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Pixie CMS versions 1.01 through 1.04
Description
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the
pixie user parameter and the Referer HTTP header in a request to the default URI.Recommendations
For Pixie CMS versions 1.01 through 1.04, consider restricting access to the default URI and avoid using the
pixie user parameter until a fix is available. As a temporary workaround, restrict the Referer HTTP header to minimize the risk of exploitation.Exploit
Correção
RCE
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pixie Cms