PT-2006-4312 · Unknown · Smartsitecms

Crash_Over_Ride

·

Published

2006-07-07

·

Updated

2018-10-18

·

CVE-2006-3421

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SmartSiteCMS versions 1.0 and earlier
Description The issue allows remote attackers to execute arbitrary PHP code when the register globals setting is enabled. This is achieved by exploiting the root parameter in various PHP files, including "comment.php", "admin/comedit.php", "admin/test.php", "admin/index.php", and "admin/include/inc adminfoot.php".
Recommendations For SmartSiteCMS versions 1.0 and earlier, disable the register globals setting to prevent exploitation. Additionally, consider restricting access to the vulnerable PHP files until a fix is available. As a temporary workaround, avoid using the root parameter in the affected files.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3421

Affected Products

Smartsitecms