PT-2005-4437 · Xoops · Xoops Wf-Downloads Module
Retrogod
·
Published
2005-11-18
·
Updated
2016-10-18
·
CVE-2005-3681
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
XOOPS WF-Downloads module version 2.05
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the
list parameter in the viewcat.php file.Recommendations
For XOOPS WF-Downloads module version 2.05, consider restricting access to the viewcat.php file until a patch is available. As a temporary workaround, avoid using the
list parameter in the affected module to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Xoops Wf-Downloads Module