PT-2008-1910 · Eticket · Eticket
Published
2008-01-15
·
Updated
2018-10-15
·
CVE-2008-0266
CVSS v2.0
2.6
Low
| Vector | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
eTicket version 1.5.5.2
Description
A cross-site request forgery (CSRF) issue in the admin.php file allows remote attackers to change the administrative password and possibly perform other administrative tasks, provided they either know the old password or can leverage a separate SQL injection vulnerability.
Recommendations
For eTicket version 1.5.5.2, as a temporary workaround, consider restricting access to the admin.php file until a patch is available. Additionally, ensure that the old password is not known to unauthorized parties and mitigate the risk of SQL injection vulnerabilities to prevent leverage by attackers.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Eticket