PT-2004-3216 · Phpwebsite · Phpwebsite
David Sopas Ferreira
·
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-2322
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
phpWebSite versions prior to 0.9.3-2
Description:
The issue allows remote attackers to execute arbitrary SQL queries. This can be demonstrated using the
ANN id parameter to the announce module.Recommendations:
For versions prior to 0.9.3-2, update to version 0.9.3-2 or later to resolve the issue. As a temporary workaround, consider restricting access to the announce and notes modules until the update is applied. Avoid using the
ANN id parameter in the affected modules until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpwebsite