Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

K3Vin Mitnick

Researcher fromtunisianblackhat team
#20933of 53,633
11.9Total CVSS
Vulnerabilities · 2
Medium
2
PT-2009-3117
6.8
2009-02-06
Groone · Groone Glinks · CVE-2009-0463
**Name of the Vulnerable Software and Affected Versions** Groone GLinks version 2.1 **Description** The issue allows remote attackers to execute arbitrary PHP code via a URL in the `abspath` parameter in the includes/header.php file. **Recommendations** For Groone GLinks version 2.1, consider restricting access to the `includes/header.php` file or validating the `abspath` parameter to prevent remote file inclusion attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2009-3118
5.1
2009-02-06
Groone · Groone Gbook · CVE-2009-0464
**Name of the Vulnerable Software and Affected Versions** Groone GBook version 2.0 **Description** The issue allows remote attackers to execute arbitrary PHP code via a URL in the `abspath` parameter in the includes/header.php file. **Recommendations** For Groone GBook version 2.0, consider restricting access to the `includes/header.php` file to minimize the risk of exploitation. Avoid using the `abspath` parameter in the affected file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.