PT-2007-4886 · Gamesitescript · Gamesitescript

Xenduer77

·

Published

2007-07-10

·

Updated

2017-09-29

·

CVE-2007-3631

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GameSiteScript (gss) versions 3.1 and earlier
Description The issue is related to a SQL injection vulnerability in the index.php file. This vulnerability allows remote attackers to execute arbitrary SQL commands via the params parameter, specifically due to missing input validation of the id field.
Recommendations For GameSiteScript (gss) versions 3.1 and earlier, consider validating user input for the id field in the params parameter to prevent SQL injection attacks. As a temporary workaround, restrict access to the index.php file until a proper fix is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3631

Affected Products

Gamesitescript