PT-2012-2089 · Balitbang · Kajian Website Cms Balitbang
Publicado
2012-08-23
·
Atualizado
2017-08-29
·
CVE-2011-5111
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Kajian Website CMS Balitbang version 3.x
Description
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the
hal parameter to various modules, including the data module in alumni.php, and the lih buku, artikel, album, or berita module in index.php.Recommendations
For Kajian Website CMS Balitbang version 3.x, consider restricting access to the
hal parameter in the affected modules until a patch is available. As a temporary workaround, avoid using the hal parameter in the alumni.php and index.php files to minimize the risk of exploitation.Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Kajian Website Cms Balitbang