PT-2010-2809 · 1024 · 1024 Cms
Published
2010-03-24
·
Updated
2010-12-14
·
CVE-2010-1093
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
1024 CMS version 2.1.1
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is possible when the
magic quotes gpc setting is disabled. The issue can be exploited via the id parameter in a vp action.Recommendations
For 1024 CMS version 2.1.1, consider disabling the
vp action or restricting access to the rss.php file until a patch is available. Additionally, enabling magic quotes gpc can help mitigate this issue.Exploit
Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
1024 Cms