PT-2013-1968 · Php · Php Volunteer Management

G13

·

Published

2013-01-24

·

Updated

2013-01-29

·

CVE-2012-6504

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP Volunteer Management version 1.0.2
Description A SQL injection issue allows remote attackers to execute arbitrary SQL commands. This is achieved via the id parameter in the mods/hours/data/get hours.php file.
Recommendations For PHP Volunteer Management version 1.0.2, avoid using the id parameter in the mods/hours/data/get hours.php file until a patch is available. As a temporary workaround, consider restricting access to the get hours.php file to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-6504

Affected Products

Php Volunteer Management