PT-2006-4705 · Mospray · Mospray

Kurdish Security

·

Publicado

2006-07-25

·

Atualizado

2018-10-17

·

CVE-2006-3847

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MoSpray (aka com mospray) version 1.8 RC1
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the basedir parameter in multiple PHP files, including admin.php, details.php, modify.php, newgroup.php, newtask.php, and rss.php.
Recommendations For MoSpray (aka com mospray) version 1.8 RC1, consider restricting access to the basedir parameter in the affected PHP files until a patch is available. As a temporary workaround, avoid using the basedir parameter in the affected files to minimize the risk of exploitation.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-3847

Produtos afetados

Mospray