PT-2006-3108 · Pro Publish · Pro Publish

Aliaksandr Hartsuyeu

·

Publicado

2006-05-01

·

Atualizado

2017-07-20

·

CVE-2006-2129

CVSS v2.0

5.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Pro Publish version 2.0
Description A direct static code injection issue allows remote authenticated administrators to execute arbitrary PHP code. This is achieved by editing specific settings stored in set inc.php.
Recommendations For Pro Publish version 2.0, consider restricting access to the settings that are stored in set inc.php to prevent exploitation until a patch is available. As a temporary workaround, limit the privileges of administrators to minimize the risk of arbitrary PHP code execution.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2129

Produtos afetados

Pro Publish