HIGH
nukesentinel.php in NukeSentinel 2.5.06 and earlier uses a permissive regular expression to validate an IP address, which allows remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header, due to an incomplete patch for CVE-2007-1172
Published Mar 16, 2007
7.5
HIGHCVSS 2.0
EPSS 3.21%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.