PT-2006-6295 · Mdweb · Mdweb

Drago84

·

Published

2006-10-27

·

Updated

2017-10-19

·

CVE-2006-5587

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: MDweb versions 1.3 and earlier
Description: The issue allows remote attackers to execute arbitrary PHP code via a URL in the chemin appli parameter in specific PHP files, including "admin/inc/organisations/form org.inc.php" and "admin/inc/organisations/country insert.php".
Recommendations: For MDweb versions 1.3 and earlier, consider restricting access to the chemin appli parameter in the affected PHP files until a patch is available. As a temporary workaround, consider disabling the execution of remote PHP code in the "admin/inc/organisations/form org.inc.php" and "admin/inc/organisations/country insert.php" files. Avoid using the chemin appli parameter in the affected files until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5587

Affected Products

Mdweb