PT-2007-5321 · Berthanas · Berthanas Ziyaretci Defteri

Published

2007-08-01

·

Updated

2018-10-15

·

CVE-2007-4119

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Berthanas Ziyaretci Defteri version 2.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved through SQL injection vulnerabilities in the yonetici.asp file, specifically via the user and Pass fields.
Recommendations For Berthanas Ziyaretci Defteri version 2.0, consider restricting access to the yonetici.asp file until a patch is available, and avoid using the user and Pass fields in a manner that could facilitate SQL injection attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4119

Affected Products

Berthanas Ziyaretci Defteri