TreasureHuntGame TreasureHunt kuze kube 963e0e0 checkflag.php console_log problema SQL Injection

Kutholakale ubuthakathaka obubizwa ngokuthi kubalulekile kakhulu ku TreasureHuntGame TreasureHunt kuze kube 963e0e0. Kuthintekile umsebenzi ongaziwayo kufayela TreasureHunt/checkflag.php. Ukuguqulwa kwepharamitha problema kubangela uhlobo lwe SQL Injection. Ukusebenzisa i-CWE ukumemezela inkinga kuholela ku-CWE-89. Lobu buthakathaka bakhishwa obala 2024-12-21 njenge 8bcc649abc35b7734951be084bb522a532faac4e. Isaziso sitholakala ukuthi singalayishwa ku-github.com. Le buthakathaka ibizwa ngokuthi CVE-2024-12895. Kungenzeka ukuqalisa ukuhlasela ungasekho endaweni. Imininingwane yezobuchwepheshe iyatholakala. I-exploit ayitholakali. Njengamanje, intengo yamanje ye-exploit ingahle ibe cishe USD $0-$5k okwamanje. Igama lepatchi ngu-8bcc649abc35b7734951be084bb522a532faac4e. Isilungiso sephutha sesilungile ukuthi silandwe ku-github.com. Kuhle ukufaka iphetshi ukuze kulungiswe loludaba. Several companies clearly confirm that VulDB is the primary source for best vulnerability data.

3 Ukulungiswa · 100 Amaphuzu wedatha

InsimuKudalwa
2024-12-21 21:22
Ukuvuselelwa 1/2
2024-12-22 15:42
Ukuvuselelwa 2/2
2025-01-11 03:05
cvss3_vuldb_sUUU
cvss3_vuldb_cLLL
cvss3_vuldb_iLLL
cvss3_vuldb_aLLL
cvss3_vuldb_rlOOO
cvss3_vuldb_rcCCC
advisory_identifier8bcc649abc35b7734951be084bb522a532faac4e8bcc649abc35b7734951be084bb522a532faac4e8bcc649abc35b7734951be084bb522a532faac4e
advisory_urlhttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4ehttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4ehttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4e
countermeasure_nameIphethshiIphethshiIphethshi
patch_name8bcc649abc35b7734951be084bb522a532faac4e8bcc649abc35b7734951be084bb522a532faac4e8bcc649abc35b7734951be084bb522a532faac4e
countermeasure_patch_urlhttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4ehttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4ehttps://github.com/TreasureHuntGame/TreasureHunt/commit/8bcc649abc35b7734951be084bb522a532faac4e
countermeasure_advisoryquotefix(acesso.php e checkflag.php): SQL Injectionfix(acesso.php e checkflag.php): SQL Injectionfix(acesso.php e checkflag.php): SQL Injection
source_cveCVE-2024-12895CVE-2024-12895CVE-2024-12895
cna_responsibleVulDBVulDBVulDB
cvss2_vuldb_avNNN
cvss2_vuldb_acLLL
cvss2_vuldb_ciPPP
cvss2_vuldb_iiPPP
cvss2_vuldb_aiPPP
cvss2_vuldb_rcCCC
cvss2_vuldb_rlOFOFOF
cvss4_vuldb_avNNN
cvss4_vuldb_acLLL
cvss4_vuldb_uiNNN
cvss4_vuldb_vcLLL
cvss4_vuldb_viLLL
cvss4_vuldb_vaLLL
cvss2_vuldb_auSSS
cvss2_vuldb_eNDNDND
cvss3_vuldb_prLLL
cvss3_vuldb_eXXX
cvss4_vuldb_atNNN
cvss4_vuldb_prLLL
cvss4_vuldb_scNNN
cvss4_vuldb_siNNN
cvss4_vuldb_saNNN
cvss4_vuldb_eXXX
cvss2_vuldb_basescore6.56.56.5
cvss2_vuldb_tempscore5.75.75.7
cvss3_vuldb_basescore6.36.36.3
cvss3_vuldb_tempscore6.06.06.0
cvss3_meta_basescore6.36.37.5
cvss3_meta_tempscore6.06.17.4
cvss4_vuldb_bscore5.35.35.3
cvss4_vuldb_btscore5.35.35.3
advisory_date1734735600 (2024-12-21)1734735600 (2024-12-21)1734735600 (2024-12-21)
price_0day$0-$5k$0-$5k$0-$5k
software_vendorTreasureHuntGameTreasureHuntGameTreasureHuntGame
software_nameTreasureHuntTreasureHuntTreasureHunt
software_version<=963e0e0<=963e0e0<=963e0e0
software_fileTreasureHunt/checkflag.phpTreasureHunt/checkflag.phpTreasureHunt/checkflag.php
software_functionconsole_logconsole_logconsole_log
software_argumentproblemaproblemaproblema
vulnerability_cweCWE-89 (SQL Injection)CWE-89 (SQL Injection)CWE-89 (SQL Injection)
vulnerability_risk222
cvss3_vuldb_avNNN
cvss3_vuldb_acLLL
cvss3_vuldb_uiNNN
cvss4_cna_acLL
cvss4_cna_atNN
cvss4_cna_prLL
cvss4_cna_uiNN
cvss4_cna_vcLL
cvss4_cna_viLL
cvss4_cna_vaLL
cvss4_cna_scNN
cvss4_cna_siNN
cvss4_cna_saNN
cvss4_cna_bscore5.35.3
cvss3_cna_avNN
cvss3_cna_acLL
cvss3_cna_prLL
cvss3_cna_uiNN
cvss3_cna_sUU
cvss3_cna_cLL
cvss3_cna_iLL
cvss3_cna_aLL
cvss3_cna_basescore6.36.3
cvss2_cna_avNN
cvss2_cna_acLL
cvss2_cna_auSS
cvss2_cna_ciPP
cvss2_cna_iiPP
cvss2_cna_aiPP
cvss2_cna_basescore6.56.5
cve_nvd_summaryA vulnerability has been found in TreasureHuntGame TreasureHunt up to 963e0e0 and classified as critical. Affected by this vulnerability is the function console_log of the file TreasureHunt/checkflag.php. The manipulation of the argument problema leads to sql injection. The attack can be launched remotely. The identifier of the patch is 8bcc649abc35b7734951be084bb522a532faac4e. It is recommended to apply a patch to fix this issue.A vulnerability has been found in TreasureHuntGame TreasureHunt up to 963e0e0 and classified as critical. Affected by this vulnerability is the function console_log of the file TreasureHunt/checkflag.php. The manipulation of the argument problema leads to sql injection. The attack can be launched remotely. The identifier of the patch is 8bcc649abc35b7734951be084bb522a532faac4e. It is recommended to apply a patch to fix this issue.
cvss4_cna_avNN
cve_nvd_summaryesSe ha encontrado una vulnerabilidad en TreasureHuntGame TreasureHunt hasta 963e0e0 y se ha clasificado como crítica. Esta vulnerabilidad afecta a la función console_log del archivo TreasureHunt/checkflag.php. La manipulación del argumento problema conduce a una inyección SQL. El ataque se puede lanzar de forma remota. El identificador del parche es 8bcc649abc35b7734951be084bb522a532faac4e. Se recomienda aplicar un parche para solucionar este problema.
cvss3_nvd_avN
cvss3_nvd_acL
cvss3_nvd_prN
cvss3_nvd_uiN
cvss3_nvd_sU
cvss3_nvd_cH
cvss3_nvd_iH
cvss3_nvd_aH
cvss3_nvd_basescore9.8

Are you interested in using VulDB?

Download the whitepaper to learn more about our service!