PT-2023-10220 · Unknown · Dovgalyuk Aibattle

Dovgalyuk Ai

·

Publicado

2023-01-13

·

Atualizado

2024-08-06

·

CVE-2015-10041

CVSS v2.0

5.2

Média

VetorAV:A/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dovgalyuk AIBattle (affected versions not specified)
Description A critical vulnerability has been found in Dovgalyuk AIBattle. The issue affects the sendComments function of the file site/procedures.php. The manipulation of the text argument leads to SQL injection.
Recommendations Apply a patch to fix this issue. The patch is identified by the name e3aa4d0900167641d41cbccf53909229f00381c9. As a temporary workaround, consider disabling the sendComments function until a patch is available. Restrict access to the site/procedures.php file to minimize the risk of exploitation. Avoid using the text argument in the affected function until the issue is resolved.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-10041

Produtos afetados

Dovgalyuk Aibattle