PT-2007-4199 · Navboard · Navboard
Dj7Xpl
·
Publicado
2007-05-30
·
Atualizado
2017-10-11
·
CVE-2007-2899
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NavBoard version 2.6.0
Description
A direct static code injection issue exists, allowing remote attackers to inject arbitrary PHP code into data/config.php via multiple parameters. This is demonstrated through the
threadperpage parameter in an editconfig action.Recommendations
For NavBoard version 2.6.0, consider restricting access to the
admin config.php file and avoid using the threadperpage parameter in the editconfig action until a patch is available. As a temporary workaround, restrict modifications to the data/config.php file to prevent arbitrary code injection.Exploit
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Navboard