PT-2017-14879 · Fs · Fs Makemytrip Clone

Ihsan Sencan

+1

·

Publicado

2017-12-13

·

Atualizado

2020-09-29

·

CVE-2017-17584

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FS Makemytrip Clone version 1.0
Description The issue is related to SQL Injection, which can be exploited via the "show-flight-result.php" endpoint, specifically through the fl orig or fl dest parameters.
Recommendations For FS Makemytrip Clone version 1.0, consider restricting access to the "show-flight-result.php" endpoint or validating and sanitizing the fl orig and fl dest parameters to prevent SQL Injection attacks. As a temporary workaround, avoid using the fl orig and fl dest parameters in the affected endpoint until the issue is resolved.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-17584

Produtos afetados

Fs Makemytrip Clone