PT-2007-7269 · Bitweaver · Bitweaver

Doz

·

Publicado

2007-12-17

·

Atualizado

2018-10-15

·

CVE-2007-6412

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Bitweaver versions 2.0.0 and earlier
Description A direct static code injection issue exists when comments are enabled, allowing remote attackers to inject arbitrary PHP code via an editcomments action.
Recommendations For Bitweaver versions 2.0.0 and earlier, consider disabling the comments feature to prevent exploitation until a fix is available.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-6412

Produtos afetados

Bitweaver