PT-2006-6680 · Sphpblog · Simple Php Blog
The_3Dit0R
·
Published
2006-11-21
·
Updated
2018-10-17
·
CVE-2006-6033
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Simple PHP Blog (SPHPBlog) version 0.4.8
Description
The issue allows remote attackers to read arbitrary files and possibly include arbitrary PHP code via a .. (dot dot) sequence in the
blog theme parameter in various PHP files, including "index.php", "add cgi.php", "add link.php", "login.php", "template.php", or "contact.php".Recommendations
For Simple PHP Blog (SPHPBlog) version 0.4.8, consider restricting access to the
blog theme parameter in the affected PHP files until a patch is available. As a temporary workaround, avoid using the blog theme parameter with a .. (dot dot) sequence in the "index.php", "add cgi.php", "add link.php", "login.php", "template.php", or "contact.php" files.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Simple Php Blog