PT-2006-2486 · Php · Php Live Helper

Runvirus

·

Published

2006-03-29

·

Updated

2018-10-18

·

CVE-2006-1478

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: PHP Live Helper versions 1.8 and possibly later versions
Description: A directory traversal issue exists in initiate.php and possibly other PHP scripts, allowing remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the language cookie. This can be exploited by uploading PHP code in a gl session cookie to users.php, which causes the code to be stored in error.log, and then included by initiate.php.
Recommendations: For PHP Live Helper versions 1.8 and possibly later versions, consider restricting access to the initiate.php and users.php scripts until a patch is available. As a temporary workaround, avoid using the language cookie and restrict the use of the gl session cookie to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1478

Affected Products

Php Live Helper