PT-2007-1022 · Debian · Sitebar

Publicado

2007-10-17

·

Atualizado

2018-10-15

·

CVE-2007-5695

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SiteBar versions 3.3.8
Description: The issue concerns multiple vulnerabilities in the SiteBar package of the Debian GNU/Linux operating system, which can be exploited by a remote attacker who has passed the authentication procedure. This can lead to a breach of confidentiality, integrity, and availability of protected information. Specifically, there is an open redirect vulnerability in command.php that allows remote attackers to redirect users to arbitrary web sites via a URL in the forward parameter in a Log In action.
Recommendations: For SiteBar version 3.3.8, consider restricting access to the command.php file until a patch is available. As a temporary workaround, avoid using the forward parameter in the Log In action to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02683
CVE-2007-5695
DSA-1423-1

Produtos afetados

Sitebar