PT-2001-1463 · Newsdaemon · Newsdaemon
Published
2001-05-03
·
Updated
2017-10-10
·
CVE-2001-0234
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NewsDaemon versions prior to 0.21b
Description
The issue allows remote attackers to execute arbitrary SQL queries and gain privileges. This is achieved by exploiting a malformed
user username parameter.Recommendations
For versions prior to 0.21b, update to version 0.21b or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable parameter
user username to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Newsdaemon