PT-2009-2546 · Sailplanner · Sailplanner

Jiko

·

Published

2009-08-25

·

Updated

2017-09-29

·

CVE-2008-7077

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SailPlanner version 0.3a
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved by injecting malicious SQL code via the username and password fields.
Recommendations For SailPlanner version 0.3a, update to a version that fixes the SQL injection vulnerabilities. At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the login functionality to minimize the risk of exploitation.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-7077

Affected Products

Sailplanner