PT-2006-4139 · Anthill · Anthill
Published
2006-06-27
·
Updated
2017-07-20
·
CVE-2006-3244
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Anthill versions 0.2.6 and earlier
Description
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the
order parameter in "buglist.php" and the bug parameter in "query.php".Recommendations
For Anthill versions 0.2.6 and earlier, consider disabling the
order parameter in buglist.php and the bug parameter in query.php as a temporary workaround until a patch is available. Restrict access to buglist.php and query.php to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Anthill