PT-2005-1929 · Nuke · Nukebookmarks

Astharot

+1

·

Published

2005-03-29

·

Updated

2016-10-18

·

CVE-2005-0902

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NukeBookmarks version 0.6
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved by manipulating the category parameter in the marks.php file.
Recommendations For NukeBookmarks version 0.6, consider restricting access to the marks.php file or the category parameter to minimize the risk of exploitation until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0902

Affected Products

Nukebookmarks