PT-2006-2114 · Php · Php-Stats
Published
2006-03-09
·
Updated
2018-10-18
·
CVE-2006-1087
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHP-Stats versions 0.1.9.1 and earlier
Description
A direct static code injection issue exists in the modify config action in admin.php, allowing remote authenticated administrators to execute arbitrary PHP code via the
option new[compatibility mode] parameter. This parameter is not filtered before being stored in config.php. Additionally, this issue can be exploited by remote unauthenticated attackers when combined with an authentication bypass vulnerability related to the option[admin pass] parameter.Recommendations
For PHP-Stats versions 0.1.9.1 and earlier, update to a version that fixes this issue. As a temporary workaround, consider restricting access to the modify config action in admin.php to prevent exploitation. Avoid using the
option new[compatibility mode] parameter in the affected admin.php until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Stats