PT-2006-3108 · Pro Publish · Pro Publish
Aliaksandr Hartsuyeu
·
Published
2006-05-01
·
Updated
2017-07-20
·
CVE-2006-2129
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Pro Publish version 2.0
Description
A direct static code injection issue allows remote authenticated administrators to execute arbitrary PHP code. This is achieved by editing specific settings stored in set inc.php.
Recommendations
For Pro Publish version 2.0, consider restricting access to the settings that are stored in set inc.php to prevent exploitation until a patch is available. As a temporary workaround, limit the privileges of administrators to minimize the risk of arbitrary PHP code execution.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pro Publish