PT-2006-6561 · Apache · Apache Http Server
Kacper
·
Publicado
2006-11-14
·
Atualizado
2017-10-19
·
CVE-2006-5894
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Rama CMS versions 0.68 and earlier
Description
A directory traversal issue exists, allowing remote attackers to include and execute arbitrary local files. This is achieved by injecting PHP sequences into an Apache HTTP Server log file, which is then included, via a .. (dot dot) in the
lang cookie when register globals is enabled.Recommendations
For Rama CMS versions 0.68 and earlier, disable the
register globals setting to prevent exploitation. Consider updating the lang.php file to properly sanitize the lang cookie to prevent directory traversal attacks. As a temporary workaround, consider restricting access to the lang.php file until a patch is available.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Apache Http Server