PT-2007-2438 · Zebrafeeds · Zebrafeeds

The De@Th

·

Publicado

2007-02-21

·

Atualizado

2017-10-11

·

CVE-2007-1010

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: ZebraFeeds version 1.0
Description: The issue allows remote attackers to execute arbitrary PHP code when register globals is enabled. This is achieved by providing a URL in the zf path parameter to specific API endpoints, such as "aggregator.php" and "controller.php" in the "newsfeeds/includes/" directory.
Recommendations: For ZebraFeeds version 1.0, consider disabling the register globals setting to prevent exploitation. Additionally, restrict access to the "aggregator.php" and "controller.php" files in the "newsfeeds/includes/" directory until a fix is available. Avoid using the zf path parameter in the affected API endpoints until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1010

Produtos afetados

Zebrafeeds