PT-2010-2461 · Aspcode · Aspcode Cms
Published
2010-02-25
·
Updated
2010-02-26
·
CVE-2010-0710
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ASPCode CMS versions 1.5.8 through 2.0.0 Build 103
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the
newsid parameter when the sec parameter is set to 26.Recommendations
For ASPCode CMS versions 1.5.8 through 2.0.0 Build 103, as a temporary workaround, consider restricting access to the default.asp page or avoiding the use of the
newsid parameter when the sec parameter is 26 until a patch is available.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aspcode Cms