PT-2003-2199 · Apb · Active Php Bookmarks

Published

2003-12-31

·

Updated

2008-09-05

·

CVE-2003-1254

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Active PHP Bookmarks (APB) version 1.1.01
Description The issue allows remote attackers to execute arbitrary PHP code by modifying the APB SETTINGS parameter to reference a URL on a remote web server that contains the code. This can be achieved through various PHP files, including head.php, apb common.php, or apb view class.php.
Recommendations For Active PHP Bookmarks (APB) version 1.1.01, consider restricting access to the APB SETTINGS parameter to prevent modification and avoid using remote URLs that could contain malicious code. As a temporary workaround, restrict access to the affected PHP files until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1254

Affected Products

Active Php Bookmarks