PT-2005-4952 · Php · Php Support Tickets

Published

2005-12-15

·

Updated

2011-03-08

·

CVE-2005-4264

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP Support Tickets version 2.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is possible via the username and password fields, and the id parameter.
Recommendations For PHP Support Tickets version 2.0, consider validating and sanitizing user input for the username, password, and id parameter to prevent SQL injection attacks. As a temporary workaround, restrict access to the index.php file until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-4264

Affected Products

Php Support Tickets