PT-2009-3647 · Pixie · Pixie Cms
CVE-2009-1066
·
Publicado
2009-03-24
·
Atualizado
2024-02-14
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Pixie CMS version 1.01a
Description
The issue allows remote attackers to execute arbitrary SQL commands via the Referer HTTP header in a request, specifically in the referral function in admin/lib/lib logs.php.
Recommendations
For Pixie CMS version 1.01a, consider restricting access to the vulnerable referral function in admin/lib/lib logs.php to minimize the risk of exploitation. Avoid using the Referer HTTP header in requests to the affected function until the issue is resolved.
Exploit
Correção
RCE
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pixie Cms