PT-2006-4920 · Docpile · Docpile:We
Publicado
2006-08-11
·
Atualizado
2011-03-08
·
CVE-2006-4076
CVSS v2.0
5.1
Média
| Vetor | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
docpile:we version 0.2.2
Description
The issue allows remote attackers to execute arbitrary PHP code via a URL in the
INIT PATH parameter to various PHP files, including (1) lib/access.inc.php, (2) lib/folders.inc.php, (3) lib/init.inc.php, or (4) lib/templates.inc.php.Recommendations
For docpile:we version 0.2.2, consider restricting access to the
INIT PATH parameter in the affected API endpoints, such as lib/access.inc.php, lib/folders.inc.php, lib/init.inc.php, and lib/templates.inc.php, until a patch is available. As a temporary workaround, avoid using the INIT PATH parameter in these files to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Docpile:We