PT-2006-2486 · Php · Php Live Helper
Runvirus
·
Published
2006-03-29
·
Updated
2018-10-18
·
CVE-2006-1478
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
PHP Live Helper versions 1.8 and possibly later versions
Description:
A directory traversal issue exists in initiate.php and possibly other PHP scripts, allowing remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the
language cookie. This can be exploited by uploading PHP code in a gl session cookie to users.php, which causes the code to be stored in error.log, and then included by initiate.php.Recommendations:
For PHP Live Helper versions 1.8 and possibly later versions, consider restricting access to the initiate.php and users.php scripts until a patch is available. As a temporary workaround, avoid using the
language cookie and restrict the use of the gl session cookie to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php Live Helper