PT-2012-2118 · Diy Cms · Diy-Cms

Publicado

2012-08-31

·

Atualizado

2017-08-29

·

CVE-2011-5140

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DiY-CMS blog module version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the start parameter to various API endpoints, including "tags.php", "list.php", "index.php", "main index.php", "viewpost.php", "archive.php", "control/approve comments.php", "control/approve posts.php", and "control/viewcat.php". Additionally, the month and year parameters to "archive.php" are vulnerable.
Recommendations For DiY-CMS blog module version 1.0, consider disabling the start, month, and year parameters in the affected API endpoints until a patch is available. Restrict access to the vulnerable endpoints to minimize the risk of exploitation. Avoid using the start parameter in the affected endpoints and the month and year parameters in the "archive.php" endpoint until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-5140

Produtos afetados

Diy-Cms