PT-2005-4873 · Efiction · Efiction

Rgod

·

Publicado

2005-12-11

·

Atualizado

2008-09-05

·

CVE-2005-4174

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions eFiction versions 1.0 through 2.0
Description The issue might allow remote attackers to conduct unauthorized operations. This can be achieved by directly accessing certain scripts, specifically "install.php" or "upgrade.php". It is unclear whether this is due to a vulnerability in eFiction itself or the result of incorrect system administration practices.
Recommendations For versions 1.0 through 2.0, consider removing or restricting access to the "install.php" and "upgrade.php" scripts to prevent unauthorized operations. As a temporary workaround, restrict access to these scripts until it is determined whether the issue is due to a vulnerability in eFiction or incorrect system administration practices.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-4174

Produtos afetados

Efiction