PT-2006-3244 · Saphplesson · Saphplesson

D3Vil-0X1

·

Publicado

2006-05-09

·

Atualizado

2018-10-18

·

CVE-2006-2278

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions SaphpLesson version 3.0
Description The issue allows remote attackers to obtain the full path by manipulating certain parameters in specific PHP files. This can be achieved by passing a non-array value to the hrow parameter in show.php or index.php, the Lsnrow parameter in showcat.php, or the rows parameter in index.php.
Recommendations For SaphpLesson version 3.0, consider initializing array variables to prevent remote attackers from obtaining the full path. As a temporary workaround, restrict access to the show.php, index.php, and showcat.php files to minimize the risk of exploitation. Avoid using the hrow, Lsnrow, and rows parameters in the affected API endpoints until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2278

Produtos afetados

Saphplesson