Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

A.Nosrati

Researcher fromVIRANGAR SECURITY TEAM
#37057of 53,632
7.5Total CVSS
Vulnerabilities · 1
PT-2006-4395
7.5
2006-07-12
Sabdrimer · Sabdrimer Pro · CVE-2006-3520
**Name of the Vulnerable Software and Affected Versions** Sabdrimer Pro version 2.2.4 **Description** The issue allows remote attackers to execute arbitrary PHP code when register globals is enabled. This is achieved via a URL in the `pluginpath[0]` parameter in the skins/advanced/advanced1.php file. **Recommendations** For Sabdrimer Pro version 2.2.4, consider disabling the register globals setting to prevent exploitation. Additionally, restrict access to the skins/advanced/advanced1.php file and avoid using the `pluginpath[0]` parameter in URLs until a fix is available.