PT-2018-17122 · Mojang · Premium Minecraft Servers List+1

Publicado

2018-01-23

·

Atualizado

2018-02-15

·

CVE-2018-5749

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Minecraft Servers List Lite versions prior to commit c1cd164 Premium Minecraft Servers List versions prior to 2.0.4
Description: The issue is related to the install.php file, which does not properly sanitize input before saving database connection information in connect.php. This could allow remote attackers to execute arbitrary PHP code via the database server, database user, database password, or database name parameters.
Recommendations: For Minecraft Servers List Lite versions prior to commit c1cd164, update to a version that includes the fix from commit c1cd164. For Premium Minecraft Servers List versions prior to 2.0.4, update to version 2.0.4 or later. As a temporary workaround, consider restricting access to the install.php file and ensuring proper input validation for the database server, database user, database password, and database name parameters in connect.php.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-5749

Produtos afetados

Minecraft Servers List Lite
Premium Minecraft Servers List