PT-2009-1756 · Cms Ortus · Cms Ortus

Otmorozok428

·

Published

2009-02-25

·

Updated

2017-09-29

·

CVE-2008-6282

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: CMS Ortus versions 1.13 and earlier
Description: The issue allows remote authenticated users to execute arbitrary SQL commands. This is achieved by exploiting the city parameter in a users edit pub action to the "index.php" endpoint.
Recommendations: For CMS Ortus versions 1.13 and earlier, avoid using the city parameter in the "index.php" endpoint until a fix is available. As a temporary workaround, consider restricting access to the users edit pub action to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6282

Affected Products

Cms Ortus