PT-2022-8009 · Unknown · Itech Movie Portal Script
Marc Castejon
·
Published
2022-07-22
·
Updated
2022-07-29
·
CVE-2017-20142
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Itech Movie Portal Script version 7.36
Description
A critical issue was discovered, affecting the /artist-display.php file. The
act argument is vulnerable to SQL injection (Union) attacks, which can be initiated remotely.Recommendations
For Itech Movie Portal Script version 7.36, consider restricting access to the /artist-display.php file until a fix is available, and avoid using the
act argument in this context to minimize the risk of exploitation.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Itech Movie Portal Script