PT-2009-1550 · Bahar · Bahar Download Script

Published

2009-02-06

·

Updated

2024-02-14

·

CVE-2008-6075

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bahar Download Script version 2.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the kid parameter in the aspkat.asp file.
Recommendations For Bahar Download Script version 2.0, consider restricting access to the kid parameter in the aspkat.asp file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2008-6075

Affected Products

Bahar Download Script