PT-2007-1299 · Phpcms · Phpcms
Bugreporter
·
Publicado
2007-02-15
·
Atualizado
2017-07-29
·
CVE-2006-7020
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
phpwcms versions 1.1 through 1.1 RC4
phpwcms versions 1.2.5-DEV and earlier
Description
The issue allows remote attackers to modify HTTP headers and send spam e-mail via a spoofed HTTP Referer (
HTTP REFERER). This is due to a CRLF injection vulnerability in files such as include/inc act/act formmailer.php and possibly sample ext php/mail file form.php.Recommendations
For phpwcms versions 1.1 through 1.1 RC4, update to a version later than RC4 to resolve the issue.
For phpwcms versions 1.2.5-DEV and earlier, update to a version later than 1.2.5-DEV to resolve the issue.
As a temporary workaround, consider restricting access to the vulnerable files
act formmailer.php and mail file form.php to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpcms