PT-2006-2259 · Php+2 · Php+2

Rgod

·

Publicado

2006-03-15

·

Atualizado

2017-10-19

·

CVE-2006-1243

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple PHP Blog (SPB) versions 0.4.7.1 and earlier
Description A directory traversal issue exists, allowing remote attackers to include and execute arbitrary local files. This is achieved via directory traversal sequences and a NUL (%00) character in the blog language parameter. Attackers can inject PHP sequences into an Apache access log file, which can then be included using install05.php.
Recommendations For Simple PHP Blog (SPB) versions 0.4.7.1 and earlier, consider restricting access to the install05.php file until a patch is available. As a temporary workaround, avoid using the blog language parameter in the affected install05.php file to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1243

Produtos afetados

Apache Http Server
Php
Simple Php Blog