PT-2007-6740 · Flatnuke · Flatnuke

Kingoftheworld

·

Publicado

2007-11-01

·

Atualizado

2017-09-29

·

CVE-2007-5773

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Flatnuke version 3
Description A cross-site request forgery (CSRF) issue exists, allowing remote attackers to perform actions as administrators. This is achieved through requests that contain the pathname in the dir parameter and the filename in the ffile parameter.
Recommendations For Flatnuke version 3, consider restricting access to the File Manager module until a fix is available. As a temporary workaround, avoid using the dir and ffile parameters in requests to the index.php file.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5773

Produtos afetados

Flatnuke