PT-2012-2798 · Whmcs · Whmcs
CVE-2012-0693
·
Publicado
2012-01-14
·
Atualizado
2024-08-06
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WHMCS version 5.03
Description
The issue allows remote attackers to inject arbitrary code into a subject field via crafted ticket data in the submitticket.php file. Note that the vendor disputes this issue, stating that some details overlap with another vulnerability and that the specified version and file are incorrect.
Recommendations
For WHMCS version 5.03, consider restricting access to the submitticket.php file as a temporary workaround until the issue is resolved.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Whmcs