CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

phpCollab CMS SQL Injection Vulnerability——漏洞银行丨0DAY BANK

2016年8月25日 2061点热度 0人点赞 0条评论

漏洞类别:CGI

漏洞等级:

漏洞信息

phpCollab is an open source internet-enabled system for use in projects that require collaboration over the internet.

A SQL injection vulnerability has been identified in the 'id' parameter of the './phpcollab/users/' module.

Affected Version:
phpCollab - Content Management System version 2.5, older versions may be affected

漏洞危害

A remote attacker could exploit this vulnerability to compromise the database.

解决方案

Customers are advised to contact the Vendor to fix this vulnerability. Workaround:

The vulnerability can be patched by using a prepared statement in the 'emailusers.php' file. Also, it is advisable to disallow special characterss and escape the input and output.

0day

标签: 暂无
最后更新:2016年10月22日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me