PT-2009-1556 · Unknown · Simple Customer

T0Pp8Uzz

·

Published

2009-02-06

·

Updated

2017-09-29

·

CVE-2008-6081

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple Customer version 1.2
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved by manipulating the id parameter in the contact.php file.
Recommendations For version 1.2, consider restricting access to the contact.php file or validating and sanitizing the id parameter to prevent SQL injection attacks. As a temporary workaround, avoid using the id parameter in the contact.php file until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6081

Affected Products

Simple Customer