PT-2017-6255 · Soplanning · Soplanning

Huy-Ngoc Dau

·

Publicado

2017-08-31

·

Atualizado

2017-09-06

·

CVE-2014-8677

CVSS v2.0

3.5

Baixa

VetorAV:N/AC:M/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions SOPlanning versions 1.32 and earlier
Description The issue allows remote authenticated users to execute arbitrary PHP code via a crafted database name, given certain conditions such as access to an existing database, permissions to create arbitrary databases, the use of PHP before version 5.2, a down configuration database, or a non-writable smarty/templates c directory.
Recommendations For SOPlanning versions 1.32 and earlier, update to a version later than 1.32 to resolve the issue. As a temporary workaround, consider restricting database creation permissions and ensuring smarty/templates c is writable, while also updating PHP to version 5.2 or later.

Exploit

Correção

Improper Access Control

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-8677

Produtos afetados

Soplanning