PT-2006-3782 · Blueshoes · Blueshoes Framework

Kacper

·

Publicado

2006-06-06

·

Atualizado

2017-10-19

·

CVE-2006-2864

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions BlueShoes Framework version 4.6
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in several parameters, including APP[path][applications], APP[path][core], GLOBALS[APP][path][core], and APP[path][plugins]. This is achieved by exploiting remote file inclusion vulnerabilities in various PHP files, such as Bs Faq.class.php, fileBrowserInner.php, file.php, viewer.php, Bs ImageArchive.class.php, Bs Ml User.class.php, and Bs Wse Profile.class.php.
Recommendations For BlueShoes Framework version 4.6, consider disabling the vulnerable parameters, such as APP[path][applications], APP[path][core], GLOBALS[APP][path][core], and APP[path][plugins], to prevent exploitation until a patch is available. Restrict access to the affected PHP files, including Bs Faq.class.php, fileBrowserInner.php, file.php, viewer.php, Bs ImageArchive.class.php, Bs Ml User.class.php, and Bs Wse Profile.class.php, to minimize the risk of arbitrary PHP code execution.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2864

Produtos afetados

Blueshoes Framework