PT-2006-4429 · Mkportal · Mkportal
Stormhacker
·
Published
2006-07-13
·
Updated
2018-10-18
·
CVE-2006-3554
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MKPortal version 1.0.1 Final
Description
The issue allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the
language cookie. This can be demonstrated by using a gl session cookie to inject PHP sequences into the error.log file, which is then included by index.php with malicious commands accessible by the ind parameter.Recommendations
For MKPortal version 1.0.1 Final, consider restricting access to the
language cookie and the ind parameter in index.php to minimize the risk of exploitation. As a temporary workaround, restrict the inclusion of local files by index.php until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mkportal