Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Blue|Spy

#40408de 53,630
6.8CVSS total
Vulnerabilidades · 1
PT-2006-4704
6.8
2006-07-25
Unknown · Multibanners · CVE-2006-3846
**Name of the Vulnerable Software and Affected Versions** MultiBanners versions 1.0.1 **Description** The issue allows remote attackers to execute arbitrary PHP code via a URL in the `mosConfig absolute path` parameter in the extadminmenus.class.php file. **Recommendations** For MultiBanners version 1.0.1, avoid using the `mosConfig absolute path` parameter in the affected API endpoint until the issue is resolved. Restrict access to the extadminmenus.class.php file to minimize the risk of exploitation.