PT-2007-1299 · Phpcms · Phpcms

Bugreporter

·

Publicado

2007-02-15

·

Atualizado

2017-07-29

·

CVE-2006-7020

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions phpwcms versions 1.1 through 1.1 RC4 phpwcms versions 1.2.5-DEV and earlier
Description The issue allows remote attackers to modify HTTP headers and send spam e-mail via a spoofed HTTP Referer (HTTP REFERER). This is due to a CRLF injection vulnerability in files such as include/inc act/act formmailer.php and possibly sample ext php/mail file form.php.
Recommendations For phpwcms versions 1.1 through 1.1 RC4, update to a version later than RC4 to resolve the issue. For phpwcms versions 1.2.5-DEV and earlier, update to a version later than 1.2.5-DEV to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable files act formmailer.php and mail file form.php to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-7020

Produtos afetados

Phpcms