PT-2007-3965 · Monalbum · Monalbum
Dj7Xpl
·
Publicado
2007-05-14
·
Atualizado
2017-10-19
·
CVE-2007-2647
CVSS v2.0
6.5
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Monalbum version 0.8.7
Description
The issue allows remote authenticated users to inject arbitrary PHP code into the conf/config.inc.php file via various parameters in the admin/admin configuration.php script. The vulnerable parameters include
gadm pass, gadm user, gcfgHote, gcfgPass, gcfgUser, gclassement rep, gcontour, gfond, ggd version, ghome, ghor, gimg copyright, glangage, gmenu visible, gmini hasard, gordre rep, gpage, gracine, grech inactive, grep mini, grepertoire, gsite, gslide, gtitre, guse copyright, gversion, gvert, or gcfgBase.Recommendations
For Monalbum version 0.8.7, as a temporary workaround, consider restricting access to the admin/admin configuration.php script until a patch is available. Additionally, avoid using the vulnerable parameters in the script to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Monalbum