PT-2010-2809 · 1024 · 1024 Cms

Published

2010-03-24

·

Updated

2010-12-14

·

CVE-2010-1093

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions 1024 CMS version 2.1.1
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is possible when the magic quotes gpc setting is disabled. The issue can be exploited via the id parameter in a vp action.
Recommendations For 1024 CMS version 2.1.1, consider disabling the vp action or restricting access to the rss.php file until a patch is available. Additionally, enabling magic quotes gpc can help mitigate this issue.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1093

Affected Products

1024 Cms