PT-2005-2216 · Az · Azbb
James Bercegay
·
Publicado
2005-04-21
·
Atualizado
2017-07-11
·
CVE-2005-1200
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AZ Bulletin Board (AZbb) versions 1.0.07a through 1.0.07c
Description
The issue allows remote attackers to execute arbitrary PHP code by modifying the
dir src or abs layer parameter to reference a URL on a remote web server that contains the code.Recommendations
For AZ Bulletin Board (AZbb) versions 1.0.07a through 1.0.07c, consider restricting access to the
main index.php file until a patch is available. As a temporary workaround, avoid using the dir src and abs layer parameters in the affected file to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Azbb