PT-2006-6584 · Omnistar · Omnistar Article Manager

Benjamin Moss

+1

·

Published

2006-11-15

·

Updated

2024-02-14

·

CVE-2006-5917

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions OmniStar Article Manager (affected versions not specified)
Description The issue concerns SQL injection vulnerabilities that allow remote attackers to execute arbitrary SQL commands. This is possible via the article id parameter in "articles/comments.php" and "articles/article.php", and the page id parameter in "articles/pages.php".
Recommendations For OmniStar Article Manager, as a temporary workaround, consider restricting access to the vulnerable API endpoints "articles/comments.php", "articles/article.php", and "articles/pages.php" until a patch is available. Avoid using the article id and page id parameters in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Related Identifiers

CVE-2006-5917

Affected Products

Omnistar Article Manager