PT-2009-2403 · Sanusart · Sanus|Artificium
Gold_M
·
Publicado
2009-08-11
·
Atualizado
2017-09-29
·
CVE-2008-6934
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Sanus|artificium (aka Sanusart) Free simple guestbook PHP script versions prior to 20081111
Description:
The issue allows remote attackers to inject arbitrary PHP code into messages.txt via the
message parameter to "act.php", which is executed when "guestbook/guestbook.php" is accessed.Recommendations:
For Sanus|artificium (aka Sanusart) Free simple guestbook PHP script versions prior to 20081111, consider disabling the
act.php file or restricting access to the guestbook/guestbook.php page until a fix is available. Avoid using the message parameter in the affected API endpoint until the issue is resolved.Exploit
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sanus|Artificium