vendor:
phpCollab
by:
N/A
9,8
CVSS
CRITICAL
SQL Injections
89
CWE
Product Name: phpCollab
Affected Version From: 2.5.1
Affected Version To: 2.5.1
Patch Exists: YES
Related CWE: CVE-2017-6089
CPE: a:phpcollab:phpcollab:2.5.1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2017
[CVE-2017-6089] PhpCollab 2.5.1 Multiple SQL Injections (unauthenticated)
PhpCollab is an open source web-based project management system, that enables collaboration across the Internet. The phpCollab code does not correctly filter arguments, allowing arbitrary SQL code execution by an unauthenticated user.
Mitigation:
The vulnerable code should be filtered correctly to prevent arbitrary SQL code execution.