Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Darkgod

#48561de 53,635
5.1CVSS total
Vulnerabilidades · 1
PT-2006-3667
5.1
2006-06-01
Phpmydesktop · Phpmydesktop/Arcade · CVE-2006-2747
**Name of the Vulnerable Software and Affected Versions** PhpMyDesktop|arcade version 1.0 FINAL **Description** The issue allows remote attackers to read arbitrary files or execute PHP code. This is achieved by using a .. (dot dot) sequence and a trailing null (%00) byte in the `subsite` parameter within a showsubsite todo request to the "index.php" file. **Recommendations** For PhpMyDesktop|arcade version 1.0 FINAL, as a temporary workaround, consider restricting access to the `subsite` parameter in the "index.php" file until a patch is available. Avoid using the `subsite` parameter with a .. (dot dot) sequence and a trailing null (%00) byte in the showsubsite todo request to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.