PT-2008-3937 · Plusphp · Plusphp Short Url Multi-User Script

Dr.Toxic

·

Publicado

2008-05-28

·

Atualizado

2017-09-29

·

CVE-2008-2480

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: plusPHP Short URL Multi-User Script version 1.6
Description: The issue allows remote attackers to execute arbitrary PHP code via a URL in the pages dir parameter. This can be achieved by manipulating the pages dir parameter in the plus.php file.
Recommendations: For plusPHP Short URL Multi-User Script version 1.6, consider restricting access to the pages dir parameter to prevent remote file inclusion attacks until a patch is available. Avoid using the pages dir parameter in the affected plus.php file until the issue is resolved.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-2480

Produtos afetados

Plusphp Short Url Multi-User Script