PT-2006-7231 · Webwork · Webwork

Publicado

2006-12-18

·

Atualizado

2011-03-08

·

CVE-2006-6629

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WeBWorK versions prior to 2.3.1
Description The issue arises from an insufficiently restrictive regular expression used to determine valid macro filenames in the lib/WeBWorK/PG/Translator.pm file. This allows attackers to load arbitrary macro files whose names contain specific strings, including dangerousMacros.pl, PG.pl, or IO.pl.
Recommendations For versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6629

Produtos afetados

Webwork