PT-2009-1710 · Unknown · Simple Document Management System

Published

2009-02-21

·

Updated

2017-08-17

·

CVE-2008-6236

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Simple Document Management System (SDMS) versions 1.1.4 through 1.1.5 Simple Document Management System (SDMS) versions prior to 1.1.4
Description: The issue allows remote attackers to execute arbitrary SQL commands via the login parameter in the login.php file. This can be exploited by sending malicious input to the login endpoint.
Recommendations: For Simple Document Management System (SDMS) versions 1.1.4 through 1.1.5, consider restricting access to the login.php file until a fix is available. For Simple Document Management System (SDMS) versions prior to 1.1.4, consider upgrading to a version that is known to be secure, or restricting access to the login.php file. As a temporary workaround, consider validating and sanitizing the login parameter to prevent malicious input.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6236

Affected Products

Simple Document Management System