PT-2005-4604 · Oliver May · Oliver May Athena Php Website Administration

][Gb][

+1

·

Published

2005-11-29

·

Updated

2018-10-19

·

CVE-2005-3860

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Oliver May Athena PHP Website Administration version 0.1a
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the athena dir parameter in athena.php.
Recommendations For version 0.1a, consider restricting access to the athena.php file until a patch is available, and avoid using the athena dir parameter in the affected endpoint.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2005-3860

Affected Products

Oliver May Athena Php Website Administration