PT-2009-3003 · Php · Simple Php Newsletter

Ahmadbady

·

Publicado

2009-01-29

·

Atualizado

2017-09-29

·

CVE-2009-0340

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple PHP Newsletter version 1.5
Description The issue allows remote attackers to read arbitrary files due to multiple directory traversal vulnerabilities. This is achieved by including a .. (dot dot) in the olang parameter to API endpoints such as "mail.php" and "mailbar.php".
Recommendations For Simple PHP Newsletter version 1.5, consider restricting access to the mail.php and mailbar.php scripts until a patch is available. As a temporary workaround, avoid using the olang parameter in these API endpoints to minimize the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0340

Produtos afetados

Simple Php Newsletter