PT-2007-3573 · Punbb · Punbb
Publicado
2007-04-25
·
Atualizado
2018-10-16
·
CVE-2007-2236
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PunBB versions 1.2.14 and earlier
Description
The issue allows remote attackers to include local files, potentially leading to the execution of PHP code. This can be achieved through a cross-site scripting (XSS) attack or via the pun include tag. For example, an attacker could use admin options.php to execute PHP code from an uploaded avatar file.
Recommendations
For PunBB versions 1.2.14 and earlier, consider disabling the pun include tag and restricting the upload of files, especially avatars, until a patch is available. As a temporary workaround, restrict access to the admin options.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Punbb