PT-2006-4009 · Chipmailer · Chipmailer
Tamriel
·
Published
2006-06-21
·
Updated
2017-07-20
·
CVE-2006-3111
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Chipmailer version 1.09
Description
The issue allows remote attackers to execute arbitrary SQL commands via multiple parameters in the main.php file. The vulnerable parameters include
anfang, name, mail, anrede, vorname, nachname, gebtag, gebmonat, and gebjahr.Recommendations
For Chipmailer version 1.09, consider restricting access to the main.php file until a patch is available. As a temporary workaround, avoid using the parameters
anfang, name, mail, anrede, vorname, nachname, gebtag, gebmonat, and gebjahr in the affected API endpoint.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Chipmailer