PT-2009-2105 · Geody · Geody Labs Dagger

Cracker

·

Publicado

2009-04-07

·

Atualizado

2017-09-29

·

CVE-2008-6635

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Geody Labs Dagger - The Cutting Edge version r12feb2008
Description The issue allows remote attackers to execute arbitrary PHP code when register globals is enabled. This is achieved by providing a URL in the dir inc parameter.
Recommendations For Geody Labs Dagger - The Cutting Edge version r12feb2008, consider disabling the register globals setting to prevent exploitation. Additionally, restrict access to the skins/default.php file to minimize the risk of arbitrary PHP code execution. Avoid using the dir inc parameter in the affected endpoint until the issue is resolved.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6635

Produtos afetados

Geody Labs Dagger