PT-2006-1857 · Unknown · Skate Board
Aliaksandr Hartsuyeu
·
Publicado
2006-02-21
·
Atualizado
2017-07-20
·
CVE-2006-0810
CVSS v2.0
3.5
Baixa
| Vetor | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Skate Board version 0.9
Description
The issue allows remote authenticated administrators to execute arbitrary PHP code by modifying certain variables in config.php, possibly due to XSS or direct static code injection.
Recommendations
For Skate Board version 0.9, consider restricting access to the config.php file to prevent modification of sensitive variables until a patch is available. As a temporary workaround, review and monitor the variables in config.php for any unauthorized changes.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Skate Board