PT-2008-2429 · Auracms · Auracms
Ntos-Team
·
Published
2008-02-19
·
Updated
2017-09-29
·
CVE-2008-0811
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AuraCMS version 1.62
Description
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the
kid parameter to /mod/dl.php or /mod/links.php API endpoints, and the query parameter to search.php.Recommendations
For AuraCMS version 1.62, consider disabling the
mod/dl.php and mod/links.php scripts, as well as the search.php script, until a patch is available to prevent exploitation via the kid and query parameters. Restrict access to these API endpoints to minimize the risk of exploitation. Avoid using the kid parameter in the /mod/dl.php and /mod/links.php API endpoints and the query parameter in the search.php API endpoint until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Auracms