PT-2006-4429 · Mkportal · Mkportal

Stormhacker

·

Published

2006-07-13

·

Updated

2018-10-18

·

CVE-2006-3554

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MKPortal version 1.0.1 Final
Description The issue allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language cookie. This can be demonstrated by using a gl session cookie to inject PHP sequences into the error.log file, which is then included by index.php with malicious commands accessible by the ind parameter.
Recommendations For MKPortal version 1.0.1 Final, consider restricting access to the language cookie and the ind parameter in index.php to minimize the risk of exploitation. As a temporary workaround, restrict the inclusion of local files by index.php until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-3554

Affected Products

Mkportal