PT-2007-2470 · X News · Xpression News
Publicado
2007-02-21
·
Atualizado
2017-07-29
·
CVE-2007-1042
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Xpression News (X-News) version 1.0.1
Description:
A directory traversal issue exists in the news.php file of Xpression News (X-News) when the magic quotes gpc setting is disabled. This allows remote attackers to include arbitrary files or obtain sensitive information by using a .. (dot dot) in the
xnews-template parameter.Recommendations:
For Xpression News (X-News) version 1.0.1, consider disabling the news.php file or restricting access to it until a fix is available. Additionally, enabling the magic quotes gpc setting may help mitigate this issue. Avoid using the
xnews-template parameter with untrusted input until the issue is resolved.Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Xpression News