PT-2006-5046 · Lizge · Lizge V.20 Web Portal
Crackers_Child
·
Publicado
2006-08-18
·
Atualizado
2018-10-17
·
CVE-2006-4230
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Lizge V.20 Web Portal
Description
The issue concerns remote file inclusion vulnerabilities in the index.php file of the Lizge V.20 Web Portal. This allows remote attackers to execute arbitrary PHP code by providing a URL in the
lizge or bade parameters.Recommendations
For Lizge V.20 Web Portal, consider restricting access to the
index.php file until a patch is available. As a temporary workaround, avoid using the lizge and bade parameters in the index.php file to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Lizge V.20 Web Portal