PT-2003-2199 · Apb · Active Php Bookmarks

Publicado

2003-12-31

·

Atualizado

2008-09-05

·

CVE-2003-1254

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Active PHP Bookmarks (APB) version 1.1.01
Description The issue allows remote attackers to execute arbitrary PHP code by modifying the APB SETTINGS parameter to reference a URL on a remote web server that contains the code. This can be achieved through various PHP files, including head.php, apb common.php, or apb view class.php.
Recommendations For Active PHP Bookmarks (APB) version 1.1.01, consider restricting access to the APB SETTINGS parameter to prevent modification and avoid using remote URLs that could contain malicious code. As a temporary workaround, restrict access to the affected PHP files until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-1254

Produtos afetados

Active Php Bookmarks