Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Diesl0W

#37722de 53,639
7.5CVSS total
Vulnerabilidades · 1
PT-2007-4107
7.5
2007-05-22
Geeklog · Geeklog · CVE-2007-2793
**Name of the Vulnerable Software and Affected Versions** Geeklog versions 2.x **Description** The issue allows remote attackers to execute arbitrary PHP code via a URL in the `glConf[path system]` parameter in ImageImageMagick.php. **Recommendations** For Geeklog version 2.x, update the ImageImageMagick.php file to properly validate and sanitize the `glConf[path system]` parameter to prevent remote file inclusion attacks. As a temporary workaround, consider restricting access to the ImageImageMagick.php file until a patch is available.