PT-2006-1741 · Docmgr · Docmgr

Rgod

·

Publicado

2006-02-15

·

Atualizado

2018-10-19

·

CVE-2006-0687

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions DocMGR version 0.54.2
Description The issue concerns the process.php file in DocMGR, where the $siteModInfo variable is not initialized when a direct request is made. This allows remote attackers to include arbitrary local files or possibly remote files by modifying the includeModule and siteModInfo variable.
Recommendations For DocMGR version 0.54.2, ensure the $siteModInfo variable is properly initialized in the process.php file to prevent arbitrary file inclusion. As a temporary workaround, consider restricting access to the process.php file or validating user input to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-0687

Produtos afetados

Docmgr