PT-2006-3778 · Webspotblogging · Webspotblogging
Kacper
·
Published
2006-06-06
·
Updated
2018-10-18
·
CVE-2006-2860
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Webspotblogging version 3.0.1
Webspotblogging versions 3.0 and earlier
Description
A remote file inclusion issue allows remote attackers to execute arbitrary PHP code via a URL in the
path parameter to various PHP files, including (1) "inc/logincheck.inc.php", (2) "inc/adminheader.inc.php", (3) "inc/global.php", or (4) "inc/mainheader.inc.php".Recommendations
For Webspotblogging version 3.0.1, consider disabling the
path parameter in the affected PHP files until a patch is available.
For Webspotblogging versions 3.0 and earlier, restrict access to the vulnerable PHP files, such as "inc/logincheck.inc.php", "inc/adminheader.inc.php", "inc/global.php", and "inc/mainheader.inc.php", to minimize the risk of exploitation.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Webspotblogging