PT-2005-3882 · Phpmyfaq · Phpmyfaq
Retrogod
·
Publicado
2005-09-23
·
Atualizado
2016-10-18
·
CVE-2005-3048
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PhpMyFaq version 1.5.1
Description
The issue allows remote attackers to read arbitrary files or include arbitrary PHP files via a .. (dot dot) in the
LANGCODE parameter. This also enables direct code injection via the User Agent field in a request packet, which can be activated by using LANGCODE to reference the user tracking data file.Recommendations
For PhpMyFaq version 1.5.1, consider restricting access to the
LANGCODE parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the LANGCODE parameter in the index.php file until a patch is available. Additionally, restrict the ability to inject code via the User Agent field in request packets.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpmyfaq