PT-2007-5030 · Azdg · Azdg Dating Gold

Publicado

2007-07-15

·

Atualizado

2018-10-15

·

CVE-2007-3792

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions AzDG Dating Gold version 3.0.5
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the int path parameter to specific PHP files, including (1) header.php, (2) footer.php, or (3) secure.admin.php in the templates/ directory.
Recommendations For AzDG Dating Gold version 3.0.5, consider restricting access to the int path parameter in the affected PHP files to minimize the risk of exploitation. As a temporary workaround, restrict access to the vulnerable PHP files header.php, footer.php, and secure.admin.php until a patch is available. Avoid using the int path parameter in the affected files until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-3792

Produtos afetados

Azdg Dating Gold