PT-2007-6931 · Toko Instan · Toko Instan

K1Tk4T

·

Published

2007-11-15

·

Updated

2017-09-29

·

CVE-2007-6004

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Toko Instan version 7.6
Description The issue concerns SQL injection vulnerabilities in the index.php file. These vulnerabilities allow remote attackers to execute arbitrary SQL commands. This can be achieved via two parameters: the id parameter in an 'artikel' action or the katid parameter in a 'produk' action.
Recommendations For Toko Instan version 7.6, consider restricting access to the id and katid parameters in the 'artikel' and 'produk' actions, respectively, until a patch is available. As a temporary workaround, avoid using these parameters in the affected API endpoint.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6004

Affected Products

Toko Instan