Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Damián Saura

Researcher fromCore Security Technologies
#40713of 53,633
6.5Total CVSS
Vulnerabilities · 1
PT-2010-4701
6.5
2010-12-02
Core Technology Consulting · Bugtracker.Net · CVE-2010-3267
**Name of the Vulnerable Software and Affected Versions** BugTracker.NET versions prior to 3.4.5 **Description** The issue allows remote authenticated users to execute arbitrary SQL commands. This can be achieved via several parameters, including `qu id` in "bugs.aspx", `row id` in "delete query.aspx", `new project` or `us id` in "edit bug.aspx", and `bug list` in "massedit.aspx". **Recommendations** For versions prior to 3.4.5, update to version 3.4.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected API endpoints, such as "bugs.aspx", "delete query.aspx", "edit bug.aspx", and "massedit.aspx", and avoid using the vulnerable parameters `qu id`, `row id`, `new project`, `us id`, and `bug list` until the update is applied.