PT-2013-4467 · Todoo · Todoo Forum

Publicado

2013-05-13

·

Atualizado

2017-08-29

·

CVE-2013-3537

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Todoo Forum version 2.0
Description The issue concerns SQL injection vulnerabilities in the todooforum.php file. Remote attackers can execute arbitrary SQL commands by manipulating the id post or pg parameters.
Recommendations For Todoo Forum version 2.0, update the todooforum.php file to properly sanitize the id post and pg parameters to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the todooforum.php file until a patch is available.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-3537

Produtos afetados

Todoo Forum