PT-2006-3538 · Dschat · Dschat

Publicado

2006-05-25

·

Atualizado

2017-07-20

·

CVE-2006-2592

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DSChat version 1.0
Description The issue allows remote attackers to execute arbitrary PHP code via the Nickname field. This field is not sanitized before creating a file in a user directory.
Recommendations For DSChat version 1.0, consider sanitizing the Nickname field to prevent the execution of arbitrary PHP code. As a temporary workaround, restrict access to the file creation functionality in user directories until a proper fix is applied.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2592

Produtos afetados

Dschat