PT-2006-4216 · Mf Piadas · Mf Piadas
Botan
·
Published
2006-06-30
·
Updated
2018-10-18
·
CVE-2006-3323
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MF Piadas version 1.0
Description
A remote file inclusion issue in the admin/admin.php file allows remote attackers to execute arbitrary PHP code via the
page parameter. This can also lead to cross-site scripting, likely due to the inclusion of HTML or script files.Recommendations
For MF Piadas version 1.0, consider restricting access to the
admin/admin.php file and validating the page parameter to prevent remote file inclusion until a patch is available. As a temporary workaround, avoid using the page parameter in the affected file to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mf Piadas