PT-2006-3613 · Phpbb+1 · Phpbb+1

Publicado

2006-05-31

·

Atualizado

2018-10-18

·

CVE-2006-2693

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nivisec Hacks List versions 1.20 and earlier
Description A directory traversal issue exists in the admin/admin hacks list.php file of Nivisec Hacks List for phpBB. When register globals is enabled, remote attackers can exploit this issue by using a ".." in the phpEx parameter to read arbitrary files.
Recommendations For Nivisec Hacks List versions 1.20 and earlier, consider disabling the register globals setting to mitigate the risk of exploitation. Additionally, restrict access to the admin/admin hacks list.php file until a fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2693

Produtos afetados

Nivisec Hacks List
Phpbb