This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Castillocentral First view 2008-11-17
Product Ccleague Last view 2008-11-17
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:castillocentral:ccleague:1.2:*:pro:*:*:*:*:* 2

Related : CVE

  Date Alert Description
6.8 2008-11-17 CVE-2008-5125

admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin.

6.8 2008-11-17 CVE-2008-5123

SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands via the u parameter.

CWE : Common Weakness Enumeration

%idName
50% (1) CWE-287 Improper Authentication
50% (1) CWE-89 Improper Sanitization of Special Elements used in an SQL Command ('...

CAPEC : Common Attack Pattern Enumeration & Classification

id Name
CAPEC-21 Exploitation of Session Variables, Resource IDs and other Trusted Credentials
CAPEC-31 Accessing/Intercepting/Modifying HTTP Cookies
CAPEC-167 Lifting Sensitive Data from the Client

Open Source Vulnerability Database (OSVDB)

id Description
46471 CCleague Pro admin.php u Parameter SQL Injection
46470 CCleague Pro admin.php type Cookie Admin Authentication Bypass