PT-2005-1972 · Phpcoin · Phpcoin
James Bercegay
·
Published
2005-04-03
·
Updated
2017-07-11
·
CVE-2005-0947
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
phpCoin versions 1.2.1b and earlier
Description
The issue allows remote attackers to read and execute arbitrary files due to a directory traversal vulnerability in the auxpage.php file. This is achieved by using a .. (dot dot) in the
page parameter of the auxpage.php file.Recommendations
For phpCoin versions 1.2.1b and earlier, consider restricting access to the auxpage.php file until a patch is available. As a temporary workaround, avoid using the
page parameter in the auxpage.php file to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpcoin