PT-2015-7418 · Mysql Server · Jsp/Mysql Administrador Web

Published

2015-09-15

·

Updated

2018-10-09

·

CVE-2015-6944

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JSP/MySQL Administrador Web version 1
Description A cross-site request forgery (CSRF) issue allows remote attackers to hijack user authentication for requests that execute arbitrary SQL commands. This is achieved via the cmd parameter to the "sys/sys/listaBD2.jsp" endpoint.
Recommendations For JSP/MySQL Administrador Web version 1, consider restricting access to the "sys/sys/listaBD2.jsp" endpoint to minimize the risk of exploitation. Avoid using the cmd parameter in this endpoint until the issue is resolved.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-6944

Affected Products

Jsp/Mysql Administrador Web