PT-2009-5145 · Arab Portal · Arab Portal

Recruit

·

Published

2009-08-17

·

Updated

2017-09-19

·

CVE-2009-2781

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Arab Portal versions 2.x
Description The issue allows remote authenticated users to execute arbitrary SQL commands via the qc parameter in an "addcomment" action in the forum.php file, but only when magic quotes gpc is disabled.
Recommendations For Arab Portal version 2.x, consider disabling the addcomment action in the forum.php file until a patch is available, or ensure that magic quotes gpc is enabled to prevent exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2781

Affected Products

Arab Portal