PT-2006-4279 · Fusion · Fusion News

X0R_1

·

Published

2006-07-06

·

Updated

2017-10-19

·

CVE-2006-3387

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Fusion News version 1.0
Description A directory traversal issue exists in the sources/post.php file of Fusion News. This issue allows remote attackers to include arbitrary files via a .. (dot dot) sequence in the fil config parameter when register globals is enabled. This can be used to execute PHP code that has been injected into a log file.
Recommendations For Fusion News version 1.0, consider disabling the register globals setting to mitigate the risk of exploitation. Additionally, restrict access to the sources/post.php file and its associated parameters, such as fil config, to minimize the risk of arbitrary file inclusion. Avoid using the fil config parameter in the affected post.php file until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3387

Affected Products

Fusion News