PT-2006-4920 · Docpile · Docpile:We

Publicado

2006-08-11

·

Atualizado

2011-03-08

·

CVE-2006-4076

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions docpile:we version 0.2.2
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the INIT PATH parameter to various PHP files, including (1) lib/access.inc.php, (2) lib/folders.inc.php, (3) lib/init.inc.php, or (4) lib/templates.inc.php.
Recommendations For docpile:we version 0.2.2, consider restricting access to the INIT PATH parameter in the affected API endpoints, such as lib/access.inc.php, lib/folders.inc.php, lib/init.inc.php, and lib/templates.inc.php, until a patch is available. As a temporary workaround, avoid using the INIT PATH parameter in these files to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4076

Produtos afetados

Docpile:We