PT-2007-3987 · Php · Phpchain
Publicado
2007-05-14
·
Atualizado
2017-07-29
·
CVE-2007-2670
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PHPChain versions 1.0 and earlier
Description
The issue allows remote attackers to obtain the installation path by providing invalid values for the
catid parameter to settings.php or cat.php, which can be exploited for XSS manipulations.Recommendations
For PHPChain versions 1.0 and earlier, consider restricting access to the settings.php and cat.php files until a fix is available, and avoid using the
catid parameter in these files to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Phpchain