PT-2002-2889 · Unknown · Gender Mod
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2176
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Gender MOD version 1.1.3
Description:
The issue allows remote attackers to gain administrative access. This is achieved via the
user level parameter in the "User Profile" page, which is vulnerable to SQL injection.Recommendations:
For Gender MOD version 1.1.3, consider restricting access to the User Profile page until a patch is available. As a temporary workaround, avoid using the
user level parameter in the affected page to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gender Mod