PT-2005-4693 · Unknown · Bedeng Psp

Published

2005-12-01

·

Updated

2008-10-03

·

CVE-2005-3953

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bedeng PSP version 1.1
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the cwhere parameter to API endpoints such as "index.php" and "download.php", or the ckode parameter to "baca.php".
Recommendations For Bedeng PSP version 1.1, consider restricting access to the cwhere parameter in "index.php" and "download.php", and the ckode parameter in "baca.php" to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3953

Affected Products

Bedeng Psp