PT-2007-4529 · Elxis · Elxis Cms
Nico Leidecker
·
Published
2007-06-18
·
Updated
2018-10-16
·
CVE-2007-3250
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Elxis CMS versions prior to 2006.4 20070613
Description:
The issue allows remote attackers to execute arbitrary SQL commands via the
mb tracker cookie in the mod banners.php file. This can lead to unauthorized access and manipulation of database content. The product was patched without updating the version number, so later downloads of version 2006.4 are not affected.Recommendations:
For versions prior to 2006.4 20070613, as a temporary workaround, consider restricting access to the
mod banners.php file until a patched version can be downloaded. Avoid using the mb tracker cookie in the affected module to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Elxis Cms