PT-2011-1789 · Zuitu · Zuitu

Published

2011-10-05

·

Updated

2017-08-29

·

CVE-2010-4854

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Zuitu version 1.6
Description The issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the id parameter in a consume action in the "ajax/coupon.php" file when magic quotes gpc is disabled.
Recommendations For Zuitu version 1.6, consider disabling the consume action in "ajax/coupon.php" or restricting access to it until a patch is available. Additionally, enabling magic quotes gpc can help mitigate the risk of SQL injection attacks.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-4854

Affected Products

Zuitu