PT-2011-5123 · Vik Realty · Com Vikrealestate

Chris Russell

·

Publicado

2011-12-15

·

Atualizado

2012-02-09

·

CVE-2011-4823

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions com vikrealestate version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the contract parameter in a results action and the imm parameter in a show action to "index.php".
Recommendations For version 1.0, consider restricting access to the vulnerable parameters contract and imm in the respective actions until a patch is available. Avoid using the contract parameter in the results action and the imm parameter in the show action to "index.php" until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-4823

Produtos afetados

Com Vikrealestate