PT-2006-4312 · Unknown · Smartsitecms
Crash_Over_Ride
·
Published
2006-07-07
·
Updated
2018-10-18
·
CVE-2006-3421
CVSS v2.0
5.1
Medium
| Vector | AV:N/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SmartSiteCMS versions 1.0 and earlier
Description
The issue allows remote attackers to execute arbitrary PHP code when the register globals setting is enabled. This is achieved by exploiting the
root parameter in various PHP files, including "comment.php", "admin/comedit.php", "admin/test.php", "admin/index.php", and "admin/include/inc adminfoot.php".Recommendations
For SmartSiteCMS versions 1.0 and earlier, disable the register globals setting to prevent exploitation. Additionally, consider restricting access to the vulnerable PHP files until a fix is available. As a temporary workaround, avoid using the
root parameter in the affected files.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Smartsitecms