PT-2006-3973 · Unknown · Doublespeak

·

CVE-2006-3069

·

Published

2006-06-19

·

Updated

2024-08-07

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions DoubleSpeak version 0.1
Description The issue allows remote attackers to execute arbitrary PHP code via the config[private] parameter in multiple files, such as "index.php", "faq.php", and "hardware.php", when register globals is enabled. However, this issue has been disputed by multiple third-party researchers, who state that config[private] is initialized in an include file before being used.
Recommendations For DoubleSpeak version 0.1, consider disabling the use of the config[private] parameter in affected files until a patch is available. Additionally, disabling register globals can help mitigate the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3069

Affected Products

Doublespeak