PT-2005-3297 · Php · Phpnews
Rst
·
Published
2005-07-26
·
Updated
2016-10-18
·
CVE-2005-2383
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHPNews version 1.2.5
Description
The issue allows remote attackers to execute arbitrary SQL commands via the
user parameter in an HTTP POST request. This is a SQL injection vulnerability in the auth.php file.Recommendations
For PHPNews version 1.2.5, consider restricting access to the auth.php file or validating and sanitizing the
user parameter to prevent SQL injection attacks. As a temporary workaround, avoid using the user parameter in the affected HTTP POST request until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpnews