PT-2011-4954 · Pmwiki · Pmwiki
Egidio Romano
+1
·
Publicado
2011-12-22
·
Atualizado
2012-01-12
·
CVE-2011-4453
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PmWiki versions prior to 2.2.35
Description
The issue allows remote attackers to execute arbitrary code via PHP sequences in a crafted order parameter in a pagelist directive. This leads to unintended use of the PHP create function function, potentially enabling code execution.
Recommendations
For versions prior to 2.2.35, update to version 2.2.35 or later to resolve the issue. As a temporary workaround, consider restricting access to the pagelist directive to minimize the risk of exploitation.
Exploit
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Pmwiki