PT-2010-2680 · Saskia · Saskia'S Shopsystem
Publicado
2010-03-09
·
Atualizado
2017-08-17
·
CVE-2010-0957
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Saskia's Shopsystem versions beta1 and earlier
Description
A directory traversal issue exists, allowing remote attackers to include and execute arbitrary local files. This is achieved by using directory traversal sequences in the
id parameter of the content.php file.Recommendations
For versions beta1 and earlier, consider restricting access to the content.php file until a patch is available. As a temporary workaround, avoid using the
id parameter in the content.php file to minimize the risk of exploitation.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Saskia'S Shopsystem