PT-2006-2682 · Squery · Osquery

Codexploder

·

Publicado

2006-04-10

·

Atualizado

2024-02-14

·

CVE-2006-1688

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: SQuery versions 4.5 and earlier
Description: The issue allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter to scripts in the lib directory, including multiple PHP files such as ase.php, devi.php, doom3.php, and others. This issue only occurs when register globals is disabled.
Recommendations: For SQuery versions 4.5 and earlier, consider disabling the libpath parameter or restricting access to the lib directory to minimize the risk of exploitation. Additionally, ensure that register globals is enabled to prevent this issue, but be aware of the potential security implications of this setting.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-1688

Produtos afetados

Osquery