PT-2006-6557 · Superfreaker Studios · Usupport
Ajann
·
Published
2006-11-14
·
Updated
2017-10-19
·
CVE-2006-5890
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Superfreaker Studios USupport version 1.0
Description
A SQL injection issue exists in the detail.asp file, allowing remote attackers to execute arbitrary SQL commands by manipulating the
id parameter in the API endpoint "/detail.asp".Recommendations
For Superfreaker Studios USupport version 1.0, avoid using the
id parameter in the detail.asp file until a fix is available. As a temporary workaround, consider restricting access to the detail.asp file to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Usupport