PT-2007-1583 · Apache · Apache Http Server

Kw3[R]Ln

·

Publicado

2007-01-05

·

Atualizado

2017-10-19

·

CVE-2007-0098

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions VerliAdmin versions 0.3 and earlier
Description The issue allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang cookie. This can be achieved by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php, but only when magic quotes gpc is disabled.
Recommendations For VerliAdmin versions 0.3 and earlier, consider disabling the language.php file or restricting access to it until a patch is available. Additionally, enabling magic quotes gpc can mitigate this issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0098

Produtos afetados

Apache Http Server