PT-2007-3242 · Sky Gunning · Sky Gunning Myspeach
Xst3Nz
·
Publicado
2007-04-09
·
Atualizado
2017-10-11
·
CVE-2007-1896
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Sky GUNNING MySpeach versions 3.0.7 and earlier
Description:
The issue allows remote attackers to include arbitrary local files via a .. (dot dot) and trailing %00 (NULL) in a
my ms[root] cookie. This can be exploited by sending a crafted cookie to the chat.php file.Recommendations:
For Sky GUNNING MySpeach versions 3.0.7 and earlier, as a temporary workaround, consider restricting access to the chat.php file until a patch is available. Avoid using the
my ms[root] cookie in the affected chat.php file until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sky Gunning Myspeach