PT-2006-6688 · Laurent Van Den Reysen · Work System E-Commerce

Slimtim10

·

Publicado

2006-11-22

·

Atualizado

2018-10-17

·

CVE-2006-6041

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Laurent Van den Reysen WORK system e-commerce versions 3.0.2 through 3.0.3
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the g include parameter to various files, including (1) "index.php", (2) "module/forum/forum.php", (3) unspecified files under "module/", and (4) unspecified files under "administration/module/".
Recommendations For versions 3.0.2 through 3.0.3, update to version 3.0.4 to resolve the issue.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-6041

Produtos afetados

Work System E-Commerce