Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

N3Tr00T3R

Pesquisador dePersian Boys Hacking Team
#27518de 53,639
9.3CVSS total
Vulnerabilidades · 1
PT-2008-4624
9.3
2008-07-18
Pragyan · Pragyan Cms · CVE-2008-3207
Name of the Vulnerable Software and Affected Versions: Pragyan CMS version 2.6.2 Description: The issue allows remote attackers to execute arbitrary PHP code when register globals is enabled. This is achieved via a URL in the `sourceFolder` or `moduleFolder` parameters. Recommendations: For Pragyan CMS version 2.6.2, consider disabling the register globals setting to prevent exploitation. Additionally, restrict access to the cms/modules/form.lib.php module to minimize the risk of arbitrary PHP code execution. Avoid using the `sourceFolder` and `moduleFolder` parameters in URLs until the issue is resolved.