PT-2005-3175 · Iphotoalbum · Photoalbum

Gold_M

·

Publicado

2005-07-12

·

Atualizado

2017-10-11

·

CVE-2005-2246

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: iPhotoAlbum version 1.1
Description: The issue allows remote attackers to execute arbitrary code. This is achieved via the doc path parameter to "getpage.php" or the set menu parameter to "lib/static/header.php".
Recommendations: For iPhotoAlbum version 1.1, consider restricting access to the "getpage.php" and "lib/static/header.php" files until a patch is available. Avoid using the doc path and set menu parameters in the affected API endpoints until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2246

Produtos afetados

Photoalbum