PT-2015-4226 · Microweber · Microweber Cms
Publicado
2015-01-03
·
Atualizado
2015-01-05
·
CVE-2014-9464
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microweber CMS version 0.95 before 20141209
Description
The issue allows remote attackers to execute arbitrary SQL commands via the
category parameter when displaying a category, related to the $parent id variable. This is a SQL injection vulnerability in the Category.php file.Recommendations
For Microweber CMS version 0.95 before 20141209, update to a version released after 20141209 to resolve the issue. As a temporary workaround, consider restricting access to the Category.php file or avoiding the use of the
category parameter until the issue is resolved.Exploit
Correção
RCE
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Microweber Cms