PT-2007-3650 · Unknown · Minibb Forum

Cold Zero

·

Publicado

2007-04-26

·

Atualizado

2017-10-11

·

CVE-2007-2317

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MiniBB Forum versions 1.5a and earlier
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the absolute path parameter to bb plugins.php in certain components or configuration.php. This can be exploited through different vectors, including components/minibb/ or components/com minibb.
Recommendations For MiniBB Forum versions 1.5a and earlier, consider disabling access to bb plugins.php in components/minibb/ and components/com minibb, and restrict modifications to configuration.php until a fix is available. Avoid using the absolute path parameter in the affected API endpoints until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2317

Produtos afetados

Minibb Forum