PT-2006-3778 · Webspotblogging · Webspotblogging

Kacper

·

Published

2006-06-06

·

Updated

2018-10-18

·

CVE-2006-2860

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Webspotblogging version 3.0.1 Webspotblogging versions 3.0 and earlier
Description A remote file inclusion issue allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to various PHP files, including (1) "inc/logincheck.inc.php", (2) "inc/adminheader.inc.php", (3) "inc/global.php", or (4) "inc/mainheader.inc.php".
Recommendations For Webspotblogging version 3.0.1, consider disabling the path parameter in the affected PHP files until a patch is available. For Webspotblogging versions 3.0 and earlier, restrict access to the vulnerable PHP files, such as "inc/logincheck.inc.php", "inc/adminheader.inc.php", "inc/global.php", and "inc/mainheader.inc.php", to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-2860

Affected Products

Webspotblogging