PT-2006-5392 · Php · Php-Revista

Sirdarckcat

·

Published

2006-09-07

·

Updated

2018-10-17

·

CVE-2006-4606

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions php-Revista version 1.1.2
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via several parameters in different PHP files, including the id temas parameter in "busqueda tema.php", the cadena parameter in "busqueda.php", the id autor parameter in "autor.php", the email parameter in "lista.php", and the id articulo parameter in "articulo.php".
Recommendations For php-Revista version 1.1.2, consider validating and sanitizing user input for the id temas, cadena, id autor, email, and id articulo parameters to prevent SQL injection attacks. As a temporary workaround, restrict access to the affected PHP files until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4606

Affected Products

Php-Revista