PT-2006-3356 · Popphoto · Popphoto Studio

CVE-2006-2395

·

Publicado

2006-05-16

·

Atualizado

2024-02-14

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions PopPhoto Studio versions 3.5.4 and earlier
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the include path parameter, specifically through the cfg['popphoto base path'] variable in the resources/includes/popp.config.loader.inc.php file.
Recommendations For PopPhoto Studio versions 3.5.4 and earlier, update to a version that includes the patch for this issue, as the previous vendor has already released an update that fixes the problem.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-2395

Produtos afetados

Popphoto Studio