PT-2005-1675 · Pblang · Pblang
Th3_R@V3N
·
Published
2005-03-01
·
Updated
2017-07-11
·
CVE-2005-0630
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PBLang version 4.63
Description
The issue allows remote authenticated users to read arbitrary files. This is achieved by providing a full pathname in the
orig parameter in the sendpm.php file.Recommendations
For PBLang version 4.63, consider restricting access to the
sendpm.php file until a patch is available, or avoid using the orig parameter with full pathnames to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pblang