PT-2006-1856 · Unknown · Skate Board
Aliaksandr Hartsuyeu
·
Published
2006-02-21
·
Updated
2017-07-20
·
CVE-2006-0809
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Skate Board version 0.9
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is possible via the
usern parameter in the "sendpass.php" endpoint, and the usern and passwd parameters, as well as the sf cookie cookie in the "login.php" and "logged.php" endpoints.Recommendations
For Skate Board version 0.9, consider restricting access to the "sendpass.php", "login.php", and "logged.php" endpoints until a patch is available. As a temporary workaround, avoid using the
usern and passwd parameters in these endpoints. Additionally, restrict the use of the sf cookie cookie to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Skate Board