PT-2005-1738 · Php · Phpweblog

Published

2005-03-07

·

Updated

2008-09-05

·

CVE-2005-0698

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHPWebLog versions 0.5.3 and earlier
Description A remote file inclusion issue allows remote attackers to execute arbitrary PHP code by modifying specific parameters to reference a URL on a remote web server that contains the code. The issue can be exploited by altering the G PATH parameter to init.inc.php or the PATH parameter to index.php.
Recommendations For PHPWebLog versions 0.5.3 and earlier, consider restricting access to the init.inc.php and index.php files to minimize the risk of exploitation. Avoid using the G PATH parameter to init.inc.php and the PATH parameter to index.php until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0698

Affected Products

Phpweblog