PT-2005-4338 · Invision · Invision Power Board

Publicado

2005-11-16

·

Atualizado

2018-10-19

·

CVE-2005-3549

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Invision Power Board version 2.0.1
Description A direct code injection issue in the Task Manager allows limited remote attackers to execute arbitrary code. This is achieved by referencing a file in the Task PHP File To Run field and then selecting Run Task Now.
Recommendations For Invision Power Board version 2.0.1, consider restricting access to the Task Manager or removing the ability to reference external files in the Task PHP File To Run field until a fix is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-3549

Produtos afetados

Invision Power Board