PT-2007-2067 · Unknown · Advanced Guestbook

Publicado

2007-05-09

·

Atualizado

2018-10-16

·

CVE-2007-0609

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Advanced Guestbook version 2.4.2
Description The issue allows remote attackers to bypass .htaccess settings and execute arbitrary PHP local files or read arbitrary local templates. This is achieved by sending a request to index.php with a lang cookie containing a .. (dot dot) followed by a filename without its .php extension.
Recommendations For Advanced Guestbook version 2.4.2, consider restricting access to the lang cookie to prevent manipulation, and ensure that .htaccess settings are properly configured to prevent directory traversal attacks. As a temporary workaround, consider disabling the execution of arbitrary PHP files until a patch is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-0609

Produtos afetados

Advanced Guestbook