PT-2006-5635 · David Bennett · Php-Post
Hackers Pal
·
Published
2006-09-19
·
Updated
2018-10-17
·
CVE-2006-4881
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
David Bennett PHP-Post (PHPp) versions 1.0 and earlier
Description
The issue allows remote attackers to inject arbitrary web script or HTML via several parameters in different files, including the
replyuser parameter in "pm.php", the txt jumpto parameter in "dropdown.php", the txt error and txt templatenotexist parameters in "template.php", the split parameter in files such as "editprofile.php", "search.php", "index.php", and "pm.php", and the txt login parameter in "loginline.php". Additionally, remote authenticated users can inject arbitrary web script or HTML via the txt logout parameter in "loginline.php".Recommendations
For David Bennett PHP-Post (PHPp) versions 1.0 and earlier, consider disabling the vulnerable parameters, such as
replyuser, txt jumpto, txt error, txt templatenotexist, split, txt login, and txt logout, until a patch is available. Restrict access to the affected files, including "pm.php", "dropdown.php", "template.php", "editprofile.php", "search.php", "index.php", and "loginline.php", to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Php-Post