PT-2003-1203 · Cafelog · Cafelog B2 Weblog Tool
Published
2003-03-18
·
Updated
2008-09-05
·
CVE-2002-1466
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CafeLog b2 Weblog Tool version 2.06pre4
Description
The issue allows remote attackers to execute arbitrary PHP code. This is achieved via the
b2inc variable when allow fopen url is enabled.Recommendations
For CafeLog b2 Weblog Tool version 2.06pre4, consider disabling the
allow fopen url setting to prevent exploitation until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cafelog B2 Weblog Tool