PT-2006-5441 · Web Provence+1 · Web Provence Sl Site+1
Kw3[R]Ln
·
Published
2006-09-09
·
Updated
2018-10-17
·
CVE-2006-4656
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Web Provence SL Site versions 1.0 and earlier
Description
A remote file inclusion issue exists, allowing remote attackers to execute arbitrary PHP code via a URL in the
spaw root parameter. This issue is actually in a third-party product, SPAW Editor PHP Edition.Recommendations
For Web Provence SL Site versions 1.0 and earlier, consider disabling the
spaw control.class.php file in the admin/editeur directory until a patch is available. Restrict access to the spaw root parameter to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Spaw Editor Php Edition
Web Provence Sl Site