PT-2006-6261 · Otscms · Open Tibia Server Content Management System

Gregstar

·

Published

2006-10-26

·

Updated

2017-10-19

·

CVE-2006-5546

CVSS v2.0

5.1

Medium

VectorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Open Tibia Server Content Management System (OTSCMS) versions 1.3.0 through 1.4.1
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][otscms][directories][classes] parameter. This can be exploited by providing a malicious URL to the vulnerable parameter, potentially leading to the execution of unauthorized PHP code.
Recommendations For Open Tibia Server Content Management System (OTSCMS) versions 1.3.0 through 1.4.1, consider restricting access to the GLOBALS[config][otscms][directories][classes] parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5546

Affected Products

Open Tibia Server Content Management System