PT-2007-3780 · Pinnacle Systems · Firefly

Alkomandoz Hacker

·

Publicado

2007-05-02

·

Atualizado

2017-10-11

·

CVE-2007-2456

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FireFly version 1.1.01
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the doc root parameter to specific PHP files, including localize.php and config.php in modules/admin/include/.
Recommendations For FireFly version 1.1.01, consider restricting access to the localize.php and config.php files in the modules/admin/include/ directory to minimize the risk of exploitation. Avoid using the doc root parameter in the affected API endpoints until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2456

Produtos afetados

Firefly