PT-2004-2962 · Linpha · Linpha
Fernando Quintero
+1
·
Published
2004-07-29
·
Updated
2017-07-11
·
CVE-2004-2066
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
LinPHA version 0.9.4
Description
The issue allows remote attackers to execute arbitrary SQL code and bypass authentication. This is achieved via the
linpha userid or linpha password cookies.Recommendations
For LinPHA version 0.9.4, update to a version that fixes the SQL injection issue to prevent remote attackers from executing arbitrary SQL code and bypassing authentication.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linpha