PT-2022-8003 · Itech · Tech Classifieds Script

Kaan Kamis

·

Published

2022-07-16

·

Updated

2022-07-19

·

CVE-2017-20136

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Itech Classifieds Script version 7.27
Description A critical issue has been discovered, allowing for SQL injection through the manipulation of the scat argument in the /subpage.php file with a specific input. This can be exploited remotely. The issue has been publicly disclosed and may be used for attacks.
Recommendations For Itech Classifieds Script version 7.27, consider restricting access to the /subpage.php file or disabling the unknown function that handles the scat argument until a patch is available. Avoid using the scat argument in the affected file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-20136

Affected Products

Tech Classifieds Script