PT-2006-2782 · Quickblogger · Quickblogger

Publicado

2006-04-14

·

Atualizado

2018-10-18

·

CVE-2006-1791

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions QuickBlogger version 1.4
Description A directory traversal issue in the acc.php file allows remote attackers to read or include arbitrary local files via the request parameter. This issue can also lead to resultant XSS when the associated include statement fails.
Recommendations For QuickBlogger version 1.4, consider restricting access to the acc.php file and the request parameter to minimize the risk of exploitation. As a temporary workaround, avoid using the request parameter in the affected API endpoint until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1791

Produtos afetados

Quickblogger