PT-2004-1248 · Phpgedview · Phpgedview

Publicado

2004-01-20

·

Atualizado

2017-10-10

·

CVE-2004-0033

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHPGEDVIEW version 2.61
Description The issue allows remote attackers to obtain sensitive information. This is achieved by exploiting the action parameter in the "admin.php" endpoint with a phpinfo command.
Recommendations For PHPGEDVIEW version 2.61, consider restricting access to the "admin.php" endpoint to minimize the risk of exploitation. As a temporary workaround, avoid using the action parameter with commands that can reveal sensitive information until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-0033

Produtos afetados

Phpgedview