PT-2006-6956 · Neocrome · Neocrome Seditio
Publicado
2006-12-07
·
Atualizado
2011-03-08
·
CVE-2006-6344
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Neocrome Seditio versions 1.10 and earlier
Description
The issue is related to multiple unspecified vulnerabilities with unknown impact and attack vectors. These vulnerabilities are associated with several files, including
plugins/ipsearch/ipsearch.admin.php, pfs/pfs.edit.inc.php, and users/users.register.inc.php in system/core. It is noted that one of the vectors might be related to SQL injection, but the specifics are not provided.Recommendations
For Neocrome Seditio versions 1.10 and earlier, consider restricting access to the vulnerable files
ipsearch.admin.php, pfs.edit.inc.php, and users.register.inc.php to minimize the risk of exploitation. Avoid using potentially vulnerable functions or parameters in these files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Neocrome Seditio