PT-2006-2486 · Php · Php Live Helper

Runvirus

·

Publicado

2006-03-29

·

Atualizado

2018-10-18

·

CVE-2006-1478

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHP Live Helper versions 1.8 and possibly later versions
Description: A directory traversal issue exists in initiate.php and possibly other PHP scripts, allowing remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie. This can be exploited by uploading PHP code in a gl session cookie to users.php, which causes the code to be stored in error.log, and then included by initiate.php.
Recommendations: For PHP Live Helper versions 1.8 and possibly later versions, consider restricting access to the initiate.php and users.php scripts until a patch is available. As a temporary workaround, avoid using the language cookie and restrict the use of the gl session cookie to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1478

Produtos afetados

Php Live Helper