PT-2009-4145 · Utopic · Utopic

Yenh4Cker

·

Published

2009-05-17

·

Updated

2018-10-10

·

CVE-2009-1661

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: uTopic version 1.0
Description: The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the rating parameter to "index.php". The vulnerability is specifically exploitable when magic quotes gpc is disabled.
Recommendations: For uTopic version 1.0, consider disabling the rating parameter in "index.php" until a patch is available, or enable magic quotes gpc to prevent SQL injection attacks.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-1661

Affected Products

Utopic