Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Lumut--

#37315de 53,635
7.5CVSS total
Vulnerabilidades · 1
PT-2011-1923
7.5
2011-11-01
Family Connections · Family Connections Who Is Chatting · CVE-2010-4988
**Name of the Vulnerable Software and Affected Versions** Family Connections Who is Chatting version 2.2.3 **Description** A remote file inclusion issue exists in the mod chatting/themes/default/header.php file, allowing remote attackers to execute arbitrary PHP code via a URL in the `TMPL[path]` parameter. **Recommendations** For Family Connections Who is Chatting version 2.2.3, consider restricting access to the `mod chatting/themes/default/header.php` file until a patch is available. As a temporary workaround, avoid using the `TMPL[path]` parameter in the affected file to minimize the risk of exploitation.