PT-2008-4883 · Phpx · Phpx
Gnix
·
Published
2008-08-06
·
Updated
2017-09-29
·
CVE-2008-3489
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHPX version 3.5.16
Description
A SQL injection issue exists in the
checkCookie function, located in includes/functions.inc.php, allowing remote attackers to execute arbitrary SQL commands by manipulating the PXL cookie.Recommendations
For PHPX version 3.5.16, consider disabling the
checkCookie function until a patch is available to prevent exploitation. Restrict access to the includes/functions.inc.php file to minimize the risk of SQL injection attacks. Avoid using the PXL cookie in the affected function until the issue is resolved.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpx