PT-2003-2199 · Apb · Active Php Bookmarks
Published
2003-12-31
·
Updated
2008-09-05
·
CVE-2003-1254
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Active PHP Bookmarks (APB) version 1.1.01
Description
The issue allows remote attackers to execute arbitrary PHP code by modifying the
APB SETTINGS parameter to reference a URL on a remote web server that contains the code. This can be achieved through various PHP files, including head.php, apb common.php, or apb view class.php.Recommendations
For Active PHP Bookmarks (APB) version 1.1.01, consider restricting access to the
APB SETTINGS parameter to prevent modification and avoid using remote URLs that could contain malicious code. As a temporary workaround, restrict access to the affected PHP files until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Active Php Bookmarks