PT-2023-10129 · Unknown · Sternenseemann Sternenblog
CVE-2014-125059
·
Publicado
2023-01-07
·
Atualizado
2024-05-17
CVSS v2.0
4.6
Média
| Vetor | AV:N/AC:H/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
sternenseemann sternenblog versions prior to 0.1.0
Description
A problematic issue has been found in sternenseemann sternenblog, affecting the
blog index function of the file main.c. The manipulation of the post path argument leads to file inclusion. The attack can be initiated remotely, with a rather high complexity and difficult exploitation. This case is considered theoretical and unlikely to occur, possibly only on obscure web servers.Recommendations
For versions prior to 0.1.0, upgrade to version 0.1.0 to address this issue. As a temporary workaround, consider restricting access to the
blog index function or the post path argument to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sternenseemann Sternenblog