PT-2005-2216 · Az · Azbb

James Bercegay

·

Published

2005-04-21

·

Updated

2017-07-11

·

CVE-2005-1200

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions AZ Bulletin Board (AZbb) versions 1.0.07a through 1.0.07c
Description The issue allows remote attackers to execute arbitrary PHP code by modifying the dir src or abs layer parameter to reference a URL on a remote web server that contains the code.
Recommendations For AZ Bulletin Board (AZbb) versions 1.0.07a through 1.0.07c, consider restricting access to the main index.php file until a patch is available. As a temporary workaround, avoid using the dir src and abs layer parameters in the affected file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1200

Affected Products

Azbb