PT-2010-2690 · Geekhelps+1 · Geekhelps Admp+1

Ahmadbady

·

Publicado

2010-03-16

·

Atualizado

2017-08-17

·

CVE-2010-0967

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Geekhelps ADMP version 1.01
Description The issue allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the style parameter to various PHP files in the themes/ directory, including (1) colorvoid/footer.php, (2) default-green/footer.php, (3) default-orange/footer.php, and (4) default/footer.php. This is possible when magic quotes gpc is disabled.
Recommendations For Geekhelps ADMP version 1.01, consider disabling the execution of PHP files in the themes/ directory or restricting access to these files until a patch is available. Additionally, enabling magic quotes gpc may help mitigate the issue.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-0967

Produtos afetados

Geekhelps Admp
Php