PT-2002-2601 · Lokwabb · Lokwabb

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-1879

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions LokwaBB version 1.2.2
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the member parameter to "member.php" or the loser parameter to "misc.php".
Recommendations For LokwaBB version 1.2.2, consider restricting access to the "member.php" and "misc.php" scripts until a patch is available. As a temporary workaround, avoid using the member and loser parameters in the affected API endpoints.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1879

Affected Products

Lokwabb