PT-2010-1508 · Xoops · Xoops Celepar Qas Module

Moudi

·

Published

2010-03-15

·

Updated

2017-09-19

·

CVE-2009-4698

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions XOOPS Celepar Qas module (affected versions not specified)
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved through SQL injection vulnerabilities in the Qas module, specifically via the codigo parameter to "aviso.php" and "imprimir.php", and the cod categoria parameter to "categoria.php".
Recommendations For the XOOPS Celepar Qas module, consider restricting access to the "aviso.php", "imprimir.php", and "categoria.php" scripts until a patch is available. As a temporary workaround, avoid using the codigo and cod categoria parameters in the affected API endpoints. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4698

Affected Products

Xoops Celepar Qas Module