PT-2007-5321 · Berthanas · Berthanas Ziyaretci Defteri
Published
2007-08-01
·
Updated
2018-10-15
·
CVE-2007-4119
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Berthanas Ziyaretci Defteri version 2.0
Description
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved through SQL injection vulnerabilities in the yonetici.asp file, specifically via the
user and Pass fields.Recommendations
For Berthanas Ziyaretci Defteri version 2.0, consider restricting access to the yonetici.asp file until a patch is available, and avoid using the
user and Pass fields in a manner that could facilitate SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Berthanas Ziyaretci Defteri