PT-2005-4650 · Unknown · Post Affiliate Pro

Published

2005-11-30

·

Updated

2009-10-09

·

CVE-2005-3910

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Post Affiliate Pro versions 2.0.4 and earlier
Description The issue allows remote attackers to include arbitrary local files, possibly due to a directory traversal vulnerability, when the md parameter in the "merchants/index.php" endpoint is exploited and magic quotes gpc is disabled.
Recommendations For Post Affiliate Pro versions 2.0.4 and earlier, consider disabling the md parameter in the merchants/index.php endpoint until a patch is available. Additionally, enabling magic quotes gpc may help mitigate the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3910

Affected Products

Post Affiliate Pro