PT-2006-1857 · Unknown · Skate Board
Aliaksandr Hartsuyeu
·
Published
2006-02-21
·
Updated
2017-07-20
·
CVE-2006-0810
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Skate Board version 0.9
Description
The issue allows remote authenticated administrators to execute arbitrary PHP code by modifying certain variables in config.php, possibly due to XSS or direct static code injection.
Recommendations
For Skate Board version 0.9, consider restricting access to the config.php file to prevent modification of sensitive variables until a patch is available. As a temporary workaround, review and monitor the variables in config.php for any unauthorized changes.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Skate Board