PT-2009-4562 · Unknown · Db Top Sites

Sirgod

·

Publicado

2009-06-18

·

Atualizado

2017-09-29

·

CVE-2009-2110

CVSS v2.0

7.6

Alta

VetorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DB Top Sites version 1.0
Description The issue allows remote attackers to include and execute arbitrary local files due to multiple directory traversal vulnerabilities. This is possible when magic quotes gpc is disabled, and a .. (dot dot) is used in the u parameter to API endpoints such as "full.php", "index.php", and "contact.php".
Recommendations For DB Top Sites version 1.0, consider disabling the execution of files through the "full.php", "index.php", and "contact.php" API endpoints until a fix is available, and ensure magic quotes gpc is enabled to prevent directory traversal attacks.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2110

Produtos afetados

Db Top Sites