PT-2007-4529 · Elxis · Elxis Cms

Nico Leidecker

·

Published

2007-06-18

·

Updated

2018-10-16

·

CVE-2007-3250

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Elxis CMS versions prior to 2006.4 20070613
Description: The issue allows remote attackers to execute arbitrary SQL commands via the mb tracker cookie in the mod banners.php file. This can lead to unauthorized access and manipulation of database content. The product was patched without updating the version number, so later downloads of version 2006.4 are not affected.
Recommendations: For versions prior to 2006.4 20070613, as a temporary workaround, consider restricting access to the mod banners.php file until a patched version can be downloaded. Avoid using the mb tracker cookie in the affected module to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3250

Affected Products

Elxis Cms