PT-2008-3094 · Matti Kiviharju · Matti Kiviharju Rekry

Sniper456

·

Published

2008-03-28

·

Updated

2017-09-29

·

CVE-2008-1535

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Matti Kiviharju rekry (aka com rekry or rekry!Joom) version 1.0.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by exploiting the op id parameter in a view action to "index.php".
Recommendations For Matti Kiviharju rekry (aka com rekry or rekry!Joom) version 1.0.0, avoid using the op id parameter in the "index.php" endpoint until the issue is resolved.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-1535

Affected Products

Matti Kiviharju Rekry