PT-2006-2057 · Johnny Vegas · Johnny Vegas Vegas Forum

Aliaksandr Hartsuyeu

·

Published

2006-03-07

·

Updated

2018-10-18

·

CVE-2006-1020

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Johnny Vegas Vegas Forum version 1.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the postid parameter in the forumlib.php file.
Recommendations For Johnny Vegas Vegas Forum version 1.0, avoid using the postid parameter in the affected API endpoint until the issue is resolved. As a temporary workaround, consider restricting access to the forumlib.php file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1020

Affected Products

Johnny Vegas Vegas Forum