PT-2007-4239 · Vbulletin Solutions · Vbulletin
Cold Z3Ro
+1
·
Publicado
2007-05-31
·
Atualizado
2017-10-11
·
CVE-2007-2941
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
vBulletin Google Yahoo Site Map (vBGSiteMap) version 2.41 for vBulletin
Description
The issue allows remote attackers to execute arbitrary PHP code via a URL in the
base parameter to API endpoints such as "vbgsitemap/vbgsitemap-config.php" or "vbgsitemap/vbgsitemap-vbseo.php".Recommendations
For vBulletin Google Yahoo Site Map (vBGSiteMap) version 2.41, consider restricting access to the
vbgsitemap-config.php and vbgsitemap-vbseo.php files until a patch is available. Avoid using the base parameter in the affected API endpoints to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Vbulletin