PT-2013-2040 · Myre · Myre Vacation Rental

D3B4G

·

Publicado

2013-08-25

·

Atualizado

2013-08-27

·

CVE-2012-6586

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MYRE Vacation Rental Software (affected versions not specified)
Description The issue concerns SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands. This can be achieved through specific parameters in certain API endpoints, such as the garage1 or bathrooms1 parameter to "vacation/1 mobile/search.php", or through unspecified input to "vacation/widgate/request more information.php".
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2012-6586

Produtos afetados

Myre Vacation Rental