PT-2006-1701 · Cpg Nuke · Cpg-Nuke Dragonfly Cms
Published
2006-02-10
·
Updated
2018-10-19
·
CVE-2006-0644
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
CPG-Nuke Dragonfly CMS version 9.0.6.1
Description
The issue concerns directory traversal vulnerabilities in the install.php file. Remote attackers can include and execute arbitrary local files using directory traversal sequences and a NUL (%00) character in the
newlang parameter and the installlang parameter in a cookie. This can be exploited to insert malicious code into a log file or to upload a malicious .png file, which is then included using install.php.Recommendations
For CPG-Nuke Dragonfly CMS version 9.0.6.1, consider restricting access to the install.php file and avoid using the
newlang and installlang parameters in cookies until a patch is available. As a temporary workaround, restrict the ability to upload files, especially .png files, to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cpg-Nuke Dragonfly Cms