PT-2006-6295 · Mdweb · Mdweb
Drago84
·
Published
2006-10-27
·
Updated
2017-10-19
·
CVE-2006-5587
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
MDweb versions 1.3 and earlier
Description:
The issue allows remote attackers to execute arbitrary PHP code via a URL in the
chemin appli parameter in specific PHP files, including "admin/inc/organisations/form org.inc.php" and "admin/inc/organisations/country insert.php".Recommendations:
For MDweb versions 1.3 and earlier, consider restricting access to the
chemin appli parameter in the affected PHP files until a patch is available.
As a temporary workaround, consider disabling the execution of remote PHP code in the "admin/inc/organisations/form org.inc.php" and "admin/inc/organisations/country insert.php" files.
Avoid using the chemin appli parameter in the affected files until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mdweb