PT-2006-2259 · Php+2 · Php+2

Rgod

·

Published

2006-03-15

·

Updated

2017-10-19

·

CVE-2006-1243

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple PHP Blog (SPB) versions 0.4.7.1 and earlier
Description A directory traversal issue exists, allowing remote attackers to include and execute arbitrary local files. This is achieved via directory traversal sequences and a NUL (%00) character in the blog language parameter. Attackers can inject PHP sequences into an Apache access log file, which can then be included using install05.php.
Recommendations For Simple PHP Blog (SPB) versions 0.4.7.1 and earlier, consider restricting access to the install05.php file until a patch is available. As a temporary workaround, avoid using the blog language parameter in the affected install05.php file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1243

Affected Products

Apache Http Server
Php
Simple Php Blog