PT-2005-2416 · Ocean12 · Ocean12 Mailing List Manager Gold
Published
2005-05-03
·
Updated
2008-09-05
·
CVE-2005-1419
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Ocean12 Mailing List Manager version 1.06
Description:
The issue allows remote attackers to execute arbitrary SQL commands via the
Admin id parameter in the admin login panel.Recommendations:
For Ocean12 Mailing List Manager version 1.06, consider restricting access to the admin login panel until a fix is available, and avoid using the
Admin id parameter in the affected API endpoint.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ocean12 Mailing List Manager Gold