PT-2009-5005 · Traidnt · Traidnt Up

Qabandi

·

Published

2009-07-27

·

Updated

2017-09-19

·

CVE-2009-2605

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Traidnt Up version 2.0
Description The issue concerns SQL injection vulnerabilities in the adminquery.php file. Remote attackers can execute arbitrary SQL commands by manipulating the trupuser and truppassword cookies to access the uploadcp/index.php endpoint.
Recommendations For Traidnt Up version 2.0, consider restricting access to the adminquery.php file and the uploadcp/index.php endpoint until a fix is available. As a temporary workaround, avoid using the trupuser and truppassword cookies in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2605

Affected Products

Traidnt Up