PT-2006-2161 · Cyboards · Cyboards Php Lite
Aliaksandr Hartsuyeu
·
Published
2006-03-10
·
Updated
2018-10-18
·
CVE-2006-1134
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CyBoards PHP Lite version 1.25
Description
The issue allows remote attackers to execute arbitrary SQL commands when the
magic quotes gpc setting is disabled. This can be achieved by manipulating the parent parameter in the "post.php" and possibly "process post.php" API endpoints.Recommendations
For CyBoards PHP Lite version 1.25, consider disabling the
parent parameter in the affected API endpoints until a patch is available. Restrict access to the "post.php" and "process post.php" endpoints to minimize the risk of exploitation. Enable the magic quotes gpc setting as a temporary workaround to mitigate the risk.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cyboards Php Lite