Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Abdi Mohamed

#48570de 53,635
5.1CVSS total
Vulnerabilidades · 1
PT-2011-2404
5.1
2011-01-20
Zwii · Zwii · CVE-2011-0505
**Name of the Vulnerable Software and Affected Versions** Zwii version 2.1.1 **Description** A directory traversal issue exists when `magic quotes gpc` is disabled and `register globals` is enabled, allowing remote attackers to include and execute arbitrary local files via directory traversal sequences in the `set[template][value]` parameter. **Recommendations** For Zwii version 2.1.1, consider disabling the `register globals` setting and enabling `magic quotes gpc` to mitigate the risk of exploitation. Additionally, restrict access to the `system/system.php` file to minimize the risk of arbitrary file inclusion. Avoid using the `set[template][value]` parameter in the affected API endpoint until the issue is resolved.