PT-2006-6276 · Comsenz · Discuzx

Rgod

·

Published

2006-10-27

·

Updated

2017-10-19

·

CVE-2006-5561

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Discuz! GBK version 5.0.0
Description: The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the cdb auth cookie in the admincp.php file.
Recommendations: For Discuz! GBK version 5.0.0, update to a version that fixes this issue to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the admincp.php file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5561

Affected Products

Discuzx