PT-2006-4991 · Chaussette · Chaussette
Drago84
·
Publicado
2006-08-16
·
Atualizado
2017-10-19
·
CVE-2006-4159
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Chaussette version 080706 and earlier
Description
The issue allows remote attackers to execute arbitrary PHP code via a URL in the
BASE parameter to various scripts in the Classes/ directory, including Evenement.php, Event.php, Event for month.php, Event for week.php, My Log.php, My Smarty.php, and possibly Event for month per day.php.Recommendations
For Chaussette version 080706 and earlier, consider restricting access to the vulnerable scripts in the Classes/ directory until a patch is available. As a temporary workaround, avoid using the
BASE parameter in the affected scripts.Exploit
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Chaussette