PT-2005-2416 · Ocean12 · Ocean12 Mailing List Manager Gold

Published

2005-05-03

·

Updated

2008-09-05

·

CVE-2005-1419

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Ocean12 Mailing List Manager version 1.06
Description: The issue allows remote attackers to execute arbitrary SQL commands via the Admin id parameter in the admin login panel.
Recommendations: For Ocean12 Mailing List Manager version 1.06, consider restricting access to the admin login panel until a fix is available, and avoid using the Admin id parameter in the affected API endpoint.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1419

Affected Products

Ocean12 Mailing List Manager Gold