PT-2007-3389 · Openads · Openads+1

Publicado

2007-04-16

·

Atualizado

2011-03-08

·

CVE-2007-2046

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Openads (phpAdsNew) versions 2.0.11 and earlier Openads for PostgreSQL (phpPgAds) versions 2.0.11 and earlier
Description The issue allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the dest parameter and the Referer HTTP header.
Recommendations For Openads (phpAdsNew) versions 2.0.11 and earlier, update to a version later than 2.0.11 to resolve the issue. For Openads for PostgreSQL (phpPgAds) versions 2.0.11 and earlier, update to a version later than 2.0.11 to resolve the issue. As a temporary workaround, consider restricting access to the adclick.php file and avoiding the use of the dest parameter in the affected API endpoint until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2046

Produtos afetados

Openads
Openads For Postgresql