PT-2006-7420 · Yrch! · Yrch!
Dr.Pantagon
+1
·
Publicado
2006-12-29
·
Atualizado
2017-10-19
·
CVE-2006-6823
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Yrch! version 1.0
Description:
A remote file inclusion issue exists in the plugins/metasearch/plug.inc.php file, allowing remote attackers to execute arbitrary PHP code via a URL in the
path parameter.Recommendations:
For Yrch! version 1.0, as a temporary workaround, consider restricting access to the
plug.inc.php file in the plugins/metasearch directory until a patch is available. Avoid using the path parameter in the affected plugin until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Yrch!