PT-2007-1439 · Hazir · Hazir Site

Dj Remix

·

Published

2007-03-07

·

Updated

2018-10-16

·

CVE-2006-7161

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Hazir Site version 2.0
Description The issue allows remote attackers to bypass authentication. This can be achieved via the k a class or the sifre parameter.
Recommendations For Hazir Site version 2.0, consider restricting access to the giris yap.asp file until a patch is available. As a temporary workaround, avoid using the sifre parameter in the affected file to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7161

Affected Products

Hazir Site