TreasureHuntGame TreasureHunt betek 963e0e0 checkflag.php console_log problema Enlakaat SQL

Un dizalc'hadenn gwallzarvoud evel kritikel zo bet dizoloet e TreasureHuntGame TreasureHunt betek 963e0e0. Kement-se a denn da ar fonksion console_log eus ar restr TreasureHunt/checkflag.php. Ar merdeiñ eus an arguzenn problema a zegas da Enlakaat SQL. Implijout CWE evit menegiñ ar gudenn a gas da CWE-89. Kement-se a zo bet embannet 21/12/2024 dindan 8bcc649abc35b7734951be084bb522a532faac4e. An aliadenn a vez kinniget evit pellgargañ war github.com. An dizurzh-mañ a vez anavezet evel CVE-2024-12895. Emañ ar galloud da lakaat an dagadenn da sevel a-bell. Titouroù teknikel a zo da gaout. N'eus ket a implijadenn hegerz. Evit poent eo priz an exploit might be approx. USD $0-$5k. Lavaret eo ez eo n'eo ket termenet. Ar c'hleuzadenn a zo prest da vezañ pellgarget war github.com. Erbedet eo da arloañ ur patche evit diskoulmañ ar gudenn-mañ. Several companies clearly confirm that VulDB is the primary source for best vulnerability data.

3 Daskemmoù · 100 Poentoù roadennoù

MaezKrouet
21/12/2024 21:22
Hizivadur 1/2
22/12/2024 15:42
Hizivadur 2/2
11/01/2025 03:05
cvss3_vuldb_sUUU
cvss3_vuldb_cLLL
cvss3_vuldb_iLLL
cvss3_vuldb_aLLL
cvss3_vuldb_rlOOO
cvss3_vuldb_rcCCC
advisory_identifier8bcc649abc35b7734951be084bb522a532faac4e8bcc649abc35b7734951be084bb522a532faac4e8bcc649abc35b7734951be084bb522a532faac4e
advisory_urlhttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4ehttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4ehttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4e
countermeasure_namePazhPazhPazh
patch_name8bcc649abc35b7734951be084bb522a532faac4e8bcc649abc35b7734951be084bb522a532faac4e8bcc649abc35b7734951be084bb522a532faac4e
countermeasure_patch_urlhttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4ehttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4ehttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4e
countermeasure_advisoryquotefix(acesso.php e checkflag.php): SQL Injectionfix(acesso.php e checkflag.php): SQL Injectionfix(acesso.php e checkflag.php): SQL Injection
source_cveCVE-2024-12895CVE-2024-12895CVE-2024-12895
cna_responsibleVulDBVulDBVulDB
cvss2_vuldb_avNNN
cvss2_vuldb_acLLL
cvss2_vuldb_ciPPP
cvss2_vuldb_iiPPP
cvss2_vuldb_aiPPP
cvss2_vuldb_rcCCC
cvss2_vuldb_rlOFOFOF
cvss4_vuldb_avNNN
cvss4_vuldb_acLLL
cvss4_vuldb_uiNNN
cvss4_vuldb_vcLLL
cvss4_vuldb_viLLL
cvss4_vuldb_vaLLL
cvss2_vuldb_auSSS
cvss2_vuldb_eNDNDND
cvss3_vuldb_prLLL
cvss3_vuldb_eXXX
cvss4_vuldb_atNNN
cvss4_vuldb_prLLL
cvss4_vuldb_scNNN
cvss4_vuldb_siNNN
cvss4_vuldb_saNNN
cvss4_vuldb_eXXX
cvss2_vuldb_basescore6.56.56.5
cvss2_vuldb_tempscore5.75.75.7
cvss3_vuldb_basescore6.36.36.3
cvss3_vuldb_tempscore6.06.06.0
cvss3_meta_basescore6.36.37.5
cvss3_meta_tempscore6.06.17.4
cvss4_vuldb_bscore5.35.35.3
cvss4_vuldb_btscore5.35.35.3
advisory_date1734735600 (21/12/2024)1734735600 (21/12/2024)1734735600 (21/12/2024)
price_0day$0-$5k$0-$5k$0-$5k
software_vendorTreasureHuntGameTreasureHuntGameTreasureHuntGame
software_nameTreasureHuntTreasureHuntTreasureHunt
software_version<=963e0e0<=963e0e0<=963e0e0
software_fileTreasureHunt/checkflag.phpTreasureHunt/checkflag.phpTreasureHunt/checkflag.php
software_functionconsole_logconsole_logconsole_log
software_argumentproblemaproblemaproblema
vulnerability_cweCWE-89 (Enlakaat SQL)CWE-89 (Enlakaat SQL)CWE-89 (Enlakaat SQL)
vulnerability_risk222
cvss3_vuldb_avNNN
cvss3_vuldb_acLLL
cvss3_vuldb_uiNNN
cvss4_cna_acLL
cvss4_cna_atNN
cvss4_cna_prLL
cvss4_cna_uiNN
cvss4_cna_vcLL
cvss4_cna_viLL
cvss4_cna_vaLL
cvss4_cna_scNN
cvss4_cna_siNN
cvss4_cna_saNN
cvss4_cna_bscore5.35.3
cvss3_cna_avNN
cvss3_cna_acLL
cvss3_cna_prLL
cvss3_cna_uiNN
cvss3_cna_sUU
cvss3_cna_cLL
cvss3_cna_iLL
cvss3_cna_aLL
cvss3_cna_basescore6.36.3
cvss2_cna_avNN
cvss2_cna_acLL
cvss2_cna_auSS
cvss2_cna_ciPP
cvss2_cna_iiPP
cvss2_cna_aiPP
cvss2_cna_basescore6.56.5
cve_nvd_summaryA vulnerability has been found in TreasureHuntGame TreasureHunt up to 963e0e0 and classified as critical. Affected by this vulnerability is the function console_log of the file TreasureHunt/checkflag.php. The manipulation of the argument problema leads to sql injection. The attack can be launched remotely. The identifier of the patch is 8bcc649abc35b7734951be084bb522a532faac4e. It is recommended to apply a patch to fix this issue.A vulnerability has been found in TreasureHuntGame TreasureHunt up to 963e0e0 and classified as critical. Affected by this vulnerability is the function console_log of the file TreasureHunt/checkflag.php. The manipulation of the argument problema leads to sql injection. The attack can be launched remotely. The identifier of the patch is 8bcc649abc35b7734951be084bb522a532faac4e. It is recommended to apply a patch to fix this issue.
cvss4_cna_avNN
cve_nvd_summaryesSe ha encontrado una vulnerabilidad en TreasureHuntGame TreasureHunt hasta 963e0e0 y se ha clasificado como crítica. Esta vulnerabilidad afecta a la función console_log del archivo TreasureHunt/checkflag.php. La manipulación del argumento problema conduce a una inyección SQL. El ataque se puede lanzar de forma remota. El identificador del parche es 8bcc649abc35b7734951be084bb522a532faac4e. Se recomienda aplicar un parche para solucionar este problema.
cvss3_nvd_avN
cvss3_nvd_acL
cvss3_nvd_prN
cvss3_nvd_uiN
cvss3_nvd_sU
cvss3_nvd_cH
cvss3_nvd_iH
cvss3_nvd_aH
cvss3_nvd_basescore9.8

Are you interested in using VulDB?

Download the whitepaper to learn more about our service!