PT-2005-3577 · Runcms · Runcms

Publicado

2005-08-24

·

Atualizado

2008-09-05

·

CVE-2005-2691

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions RunCMS versions 1.2 and earlier
Description The issue allows remote attackers to overwrite arbitrary variables, possibly enabling the execution of arbitrary code, due to the extract function being called with EXTR OVERWRITE on HTTP POST variables in the includes/common.php file.
Recommendations For RunCMS versions 1.2 and earlier, consider modifying the includes/common.php file to avoid using EXTR OVERWRITE when calling the extract function on HTTP POST variables, or apply alternative security measures to prevent variable overwrite attacks.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2691

Produtos afetados

Runcms