PT-2006-2562 · Vbook · Vbook

Published

2006-03-31

·

Updated

2018-10-18

·

CVE-2006-1563

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: VBook version 2.0
Description: A direct static code injection issue in the config.php file of VBook allows remote administrators to execute arbitrary PHP code. This code is injected into the config file, which is then included in other VBook scripts.
Recommendations: For VBook version 2.0, consider restricting access to the config.php file to prevent remote administrators from injecting arbitrary PHP code until a patch is available. As a temporary workaround, limit the privileges of remote administrators to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1563

Affected Products

Vbook