PT-2007-6853 · Picoflat · Picoflat Cms
Publicado
2007-11-10
·
Atualizado
2017-07-29
·
CVE-2007-5920
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PicoFlat CMS versions prior to 0.4.18
Description
The issue allows remote attackers to include certain files via unspecified vectors, possibly due to a directory traversal vulnerability. This can be leveraged to bypass authentication and upload files by including pico insert.php or other administrative scripts.
Recommendations
For versions prior to 0.4.18, update to version 0.4.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the pico insert.php script and other administrative scripts to minimize the risk of exploitation.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Picoflat Cms