PT-2005-2216 · Az · Azbb
James Bercegay
·
Published
2005-04-21
·
Updated
2017-07-11
·
CVE-2005-1200
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
AZ Bulletin Board (AZbb) versions 1.0.07a through 1.0.07c
Description
The issue allows remote attackers to execute arbitrary PHP code by modifying the
dir src or abs layer parameter to reference a URL on a remote web server that contains the code.Recommendations
For AZ Bulletin Board (AZbb) versions 1.0.07a through 1.0.07c, consider restricting access to the
main index.php file until a patch is available. As a temporary workaround, avoid using the dir src and abs layer parameters in the affected file to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Azbb