PT-2010-2782 · Phpkobo · Phpkobo Short Url
Publicado
2010-03-23
·
Atualizado
2010-03-24
·
CVE-2010-1061
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Phpkobo Short URL version 1.01
Description
The issue allows remote attackers to include and execute arbitrary local files via directory traversal sequences when
magic quotes gpc is disabled. This is achieved by manipulating the LANG CODE parameter in API endpoints such as "url/app/common.inc.php" and "codelib/cfg/common.inc.php".Recommendations
For Phpkobo Short URL version 1.01, consider disabling the execution of files from arbitrary locations until a patch is available. Restrict access to the
url/app/common.inc.php and codelib/cfg/common.inc.php files to minimize the risk of exploitation. Avoid using the LANG CODE parameter in the affected API endpoints until the issue is resolved. Enable magic quotes gpc to prevent directory traversal attacks.Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Phpkobo Short Url