PT-2010-3048 · Nodesforum · Nodesforum

Publicado

2010-04-12

·

Atualizado

2017-08-17

·

CVE-2010-1351

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Nodesforum versions 1.033 through 1.045
Description The issue allows remote attackers to execute arbitrary PHP code when register globals is enabled. This can be achieved via a URL in the nodesforum path from here to nodesforum folder parameter to erase user data.php and the nodesforum code path parameter to pre output.php.
Recommendations For versions 1.033 through 1.045, consider disabling the register globals setting to prevent exploitation. Additionally, restrict access to the erase user data.php and pre output.php scripts until a fix is available. Avoid using the nodesforum path from here to nodesforum folder and nodesforum code path parameters in these scripts until the issue is resolved.

Exploit

Correção

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1351

Produtos afetados

Nodesforum