PT-2005-2185 · Unknown · Mafia Blog
Dominus_Vis
·
Publicado
2005-04-18
·
Atualizado
2016-10-18
·
CVE-2005-1169
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mafia Blog version .4 BETA
Description
The issue allows remote attackers to execute arbitrary PHP code. This is possible because the admin directory is not properly protected, enabling attackers to inject code into info.php using writeinfo.php.
Recommendations
For Mafia Blog version .4 BETA, consider restricting access to the admin directory and the writeinfo.php file to prevent arbitrary PHP code execution until a proper fix is available.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mafia Blog