PT-2012-2089 · Balitbang · Kajian Website Cms Balitbang
Published
2012-08-23
·
Updated
2017-08-29
·
CVE-2011-5111
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Kajian Website CMS Balitbang version 3.x
Description
The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the
hal parameter to various modules, including the data module in alumni.php, and the lih buku, artikel, album, or berita module in index.php.Recommendations
For Kajian Website CMS Balitbang version 3.x, consider restricting access to the
hal parameter in the affected modules until a patch is available. As a temporary workaround, avoid using the hal parameter in the alumni.php and index.php files to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kajian Website Cms Balitbang