PT-2006-4991 · Chaussette · Chaussette
Drago84
·
Published
2006-08-16
·
Updated
2017-10-19
·
CVE-2006-4159
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Chaussette version 080706 and earlier
Description
The issue allows remote attackers to execute arbitrary PHP code via a URL in the
BASE parameter to various scripts in the Classes/ directory, including Evenement.php, Event.php, Event for month.php, Event for week.php, My Log.php, My Smarty.php, and possibly Event for month per day.php.Recommendations
For Chaussette version 080706 and earlier, consider restricting access to the vulnerable scripts in the Classes/ directory until a patch is available. As a temporary workaround, avoid using the
BASE parameter in the affected scripts.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chaussette