PT-2005-3577 · Runcms · Runcms
Publicado
2005-08-24
·
Atualizado
2008-09-05
·
CVE-2005-2691
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
RunCMS versions 1.2 and earlier
Description
The issue allows remote attackers to overwrite arbitrary variables, possibly enabling the execution of arbitrary code, due to the extract function being called with EXTR OVERWRITE on HTTP POST variables in the includes/common.php file.
Recommendations
For RunCMS versions 1.2 and earlier, consider modifying the includes/common.php file to avoid using EXTR OVERWRITE when calling the extract function on HTTP POST variables, or apply alternative security measures to prevent variable overwrite attacks.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Runcms