PT-2010-4420 · Av Scripts · Av Arcade 3

Saudi0Hacker

·

Published

2010-08-04

·

Updated

2017-08-17

·

CVE-2010-2933

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AV Scripts AV Arcade 3
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the ava code cookie to the "main page", related to index.php and the login task.
Recommendations For AV Scripts AV Arcade 3, consider restricting access to the ava code cookie and the login task in index.php to minimize the risk of exploitation. As a temporary workaround, avoid using the ava code cookie in the main page until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-2933

Affected Products

Av Arcade 3