PT-2007-2065 · W Agora · W-Agora

Jesper Jurcenoks

+1

·

Publicado

2007-03-20

·

Atualizado

2018-10-16

·

CVE-2007-0607

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions W-Agora (Web-Agora) version 4.2.1
Description The issue allows remote attackers to obtain application path information via a direct request to the globals.inc file, which is stored under the web document root with insufficient access control when register globals is enabled.
Recommendations For W-Agora (Web-Agora) version 4.2.1, consider disabling the register globals setting to prevent remote attackers from accessing sensitive information. Additionally, restrict access to the globals.inc file to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0607

Produtos afetados

W-Agora