PT-2007-6853 · Picoflat · Picoflat Cms

Publicado

2007-11-10

·

Atualizado

2017-07-29

·

CVE-2007-5920

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PicoFlat CMS versions prior to 0.4.18
Description The issue allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. This can be leveraged to bypass authentication and upload files by including pico insert.php or other administrative scripts.
Recommendations For versions prior to 0.4.18, update to version 0.4.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the pico insert.php script and other administrative scripts to minimize the risk of exploitation.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-5920

Produtos afetados

Picoflat Cms