PT-2006-5756 · Kietu · Kietu
William Heinbockel
·
Published
2006-09-27
·
Updated
2018-10-17
·
CVE-2006-5015
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Kietu version 3.2
Description
The issue allows remote attackers to execute arbitrary PHP code via an FTP URL in the
url hit parameter. This is a result of a PHP remote file inclusion vulnerability in the hit.php file.Recommendations
For Kietu version 3.2, consider restricting access to the
hit.php file or validating the url hit parameter to prevent the inclusion of malicious FTP URLs until a patch is available. As a temporary workaround, avoid using FTP URLs in the url hit parameter to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kietu