PT-2008-5757 · Adaptcms · Adaptcms Pro+1
Staker
·
Published
2008-10-09
·
Updated
2022-05-02
·
CVE-2008-4524
CVSS v4.0
8.9
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P |
Name of the Vulnerable Software and Affected Versions
AdaptCMS Lite version 1.3
AdaptCMS Pro version 1.3
Description
The issue concerns a SQL injection vulnerability in the "Check User" feature, specifically in the includes/check user.php file. This vulnerability allows remote attackers to execute arbitrary SQL commands by manipulating the
user name parameter.Recommendations
For AdaptCMS Lite version 1.3, avoid using the
user name parameter in the affected "Check User" feature until a patch is available.
For AdaptCMS Pro version 1.3, restrict access to the includes/check user.php file to minimize the risk of exploitation.Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adaptcms Lite
Adaptcms Pro