PT-2004-1400 · Unknown · Les Commentaires

Nourredine Himeur

·

Published

2004-03-18

·

Updated

2017-07-11

·

CVE-2004-0246

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Les Commentaires version 2.0
Description The issue concerns remote file inclusion vulnerabilities in certain PHP files, specifically fonctions.lib.php, derniers commentaires.php, and admin.php. These vulnerabilities allow remote attackers to execute arbitrary PHP code via the rep parameter.
Recommendations For Les Commentaires version 2.0, consider restricting access to the vulnerable PHP files until a patch is available. As a temporary workaround, avoid using the rep parameter in the affected files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0246

Affected Products

Les Commentaires