PT-2009-4218 · Dian Gemilang · Dgnews
Cyber-Zone
·
Published
2009-05-21
·
Updated
2017-09-29
·
CVE-2009-1746
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Dian Gemilang DGNews version 3.0 Beta
Description:
The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
id parameter in a "detail" action, specifically in the berita.php file.Recommendations:
For Dian Gemilang DGNews version 3.0 Beta, avoid using the
id parameter in the detail action of the berita.php file until a fix is available. Consider restricting access to the berita.php file to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dgnews