PT-2002-1513 · Big Sam · Big Sam

Publicado

2002-08-12

·

Atualizado

2008-09-05

·

CVE-2002-0462

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Big Sam (Built-In Guestbook Stand-Alone Module) versions 1.1.08 and earlier
Description The issue allows remote attackers to cause a denial of service or obtain the absolute path of the web server. This can be achieved by providing a very large number in the displayBegin parameter. When PHP safe mode is enabled, the web path is leaked in an error message. When safe mode is not enabled, the action consumes resources.
Recommendations For Big Sam (Built-In Guestbook Stand-Alone Module) versions 1.1.08 and earlier, consider restricting access to the bigsam guestbook.php file until a patch is available. As a temporary workaround, avoid using the displayBegin parameter with large numbers to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0462

Produtos afetados

Big Sam