PT-2007-7249 · Dwdirectory · Dwdirectory

T0Pp8Uzz

+1

·

Published

2007-12-17

·

Updated

2017-09-29

·

CVE-2007-6392

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DWdirectory versions 2.1 and earlier
Description The issue allows remote attackers to execute arbitrary SQL commands via the search parameter to the "/search" URI. This could potentially lead to unauthorized access or manipulation of database content.
Recommendations For DWdirectory versions 2.1 and earlier, consider restricting access to the "/search" URI or disabling the search parameter until a patch is available. Additionally, limiting database privileges to the minimum required for the application can help minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-6392

Affected Products

Dwdirectory