PT-2006-2114 · Php · Php-Stats

Published

2006-03-09

·

Updated

2018-10-18

·

CVE-2006-1087

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PHP-Stats versions 0.1.9.1 and earlier
Description A direct static code injection issue exists in the modify config action in admin.php, allowing remote authenticated administrators to execute arbitrary PHP code via the option new[compatibility mode] parameter. This parameter is not filtered before being stored in config.php. Additionally, this issue can be exploited by remote unauthenticated attackers when combined with an authentication bypass vulnerability related to the option[admin pass] parameter.
Recommendations For PHP-Stats versions 0.1.9.1 and earlier, update to a version that fixes this issue. As a temporary workaround, consider restricting access to the modify config action in admin.php to prevent exploitation. Avoid using the option new[compatibility mode] parameter in the affected admin.php until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1087

Affected Products

Php-Stats