PT-2005-4357 · Php · Php Icalendar+4

Robin Verton

·

Publicado

2005-11-16

·

Atualizado

2016-10-18

·

CVE-2005-3571

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions PHPCalendar version 1.0 PHPClique version 1.0 PHPCurrently version 2.0 PHPFanBase versions 2.1 through 2.2 PHPQuotes version 1.0
Description The issue allows remote attackers to include arbitrary local files via the siteurl parameter when register globals is enabled.
Recommendations For PHPCalendar version 1.0, consider disabling the siteurl parameter until a patch is available. For PHPClique version 1.0, restrict access to the vulnerable module to minimize the risk of exploitation. For PHPCurrently version 2.0, avoid using the siteurl parameter in the affected API endpoint until the issue is resolved. For PHPFanBase versions 2.1 through 2.2, as a temporary workaround, consider disabling the functionality that uses the siteurl parameter. For PHPQuotes version 1.0, restrict the use of the siteurl parameter to prevent arbitrary file inclusion.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-3571

Produtos afetados

Php Icalendar
Phpclique
Phpcurrently
Phpfanbase
Phpquotes