PT-2007-1401 · Bsq · Bsq Sitestats

Sven Krewitt

·

Published

2007-03-06

·

Updated

2018-10-16

·

CVE-2006-7123

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BSQ Sitestats versions 1.8.0 through 2.2.1
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via unspecified parameters when importing the ip-to-country.csv file, and through the HTTP Referer, HTTP User Agent, and HTTP Accept Language headers to bsqtemplateinc.php.
Recommendations For BSQ Sitestats versions 1.8.0 through 2.2.1, update to version 2.2.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7123

Affected Products

Bsq Sitestats