PT-2019-8545 · Kama · Kama-Clic-Counter

Manuel García Cárdenas

·

Publicado

2019-09-13

·

Atualizado

2019-09-16

·

CVE-2017-18614

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions kama-clic-counter plugin version 3.4.9
Description The issue concerns SQL injection via the order parameter in the "admin.php" endpoint. This allows for potential exploitation by injecting malicious SQL code.
Recommendations For kama-clic-counter plugin version 3.4.9, avoid using the order parameter in the "admin.php" endpoint until a fix is available. Consider temporarily restricting access to the admin.php endpoint to minimize the risk of exploitation.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-18614

Produtos afetados

Kama-Clic-Counter