PT-2008-5460 · Assetman · Assetman

Neo Anderson

+1

·

Published

2008-09-22

·

Updated

2017-09-29

·

CVE-2008-4161

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Assetman version 2.5b
Description The issue allows remote attackers to execute arbitrary SQL commands and conduct session fixation attacks. This is achieved through a combination of crafted order and order by parameters in a "search all" action.
Recommendations For Assetman version 2.5b, consider restricting access to the search inv.php file until a patch is available, and avoid using the order and order by parameters in the search all action to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-4161

Affected Products

Assetman