PT-2013-4467 · Todoo · Todoo Forum

Published

2013-05-13

·

Updated

2017-08-29

·

CVE-2013-3537

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Todoo Forum version 2.0
Description The issue concerns SQL injection vulnerabilities in the todooforum.php file. Remote attackers can execute arbitrary SQL commands by manipulating the id post or pg parameters.
Recommendations For Todoo Forum version 2.0, update the todooforum.php file to properly sanitize the id post and pg parameters to prevent SQL injection attacks. As a temporary workaround, consider restricting access to the todooforum.php file until a patch is available.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-3537

Affected Products

Todoo Forum