PT-2009-4768 · W3B · W3B|Cms Gaestebuch Guestbook Module

Dnx

·

Published

2009-07-07

·

Updated

2017-09-19

·

CVE-2009-2337

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions w3b|cms Gaestebuch Guestbook Module version 3.0.0
Description The issue allows remote attackers to execute arbitrary SQL commands. This is possible due to a SQL injection vulnerability when the magic quotes gpc setting is disabled. The vulnerability can be exploited via the spam id parameter.
Recommendations For version 3.0.0, consider disabling the includes/module/book/index.inc.php module until a patch is available, or restrict access to it to minimize the risk of exploitation. Avoid using the spam id parameter in the affected module until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2337

Affected Products

W3B|Cms Gaestebuch Guestbook Module