PT-2010-1359 · Sqlite · Sqlitemanager

Published

2010-01-04

·

Updated

2018-10-10

·

CVE-2009-4539

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SQLiteManager version 1.2.0
Description A cross-site scripting (XSS) issue exists, allowing remote attackers to inject arbitrary web script or HTML. This is achieved via the redirect parameter in the main.php file.
Recommendations For SQLiteManager version 1.2.0, avoid using the redirect parameter in the main.php file until a patch is available. As a temporary workaround, consider restricting access to the main.php file to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4539

Affected Products

Sqlitemanager