PT-2006-6680 · Sphpblog · Simple Php Blog

The_3Dit0R

·

Published

2006-11-21

·

Updated

2018-10-17

·

CVE-2006-6033

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Simple PHP Blog (SPHPBlog) version 0.4.8
Description The issue allows remote attackers to read arbitrary files and possibly include arbitrary PHP code via a .. (dot dot) sequence in the blog theme parameter in various PHP files, including "index.php", "add cgi.php", "add link.php", "login.php", "template.php", or "contact.php".
Recommendations For Simple PHP Blog (SPHPBlog) version 0.4.8, consider restricting access to the blog theme parameter in the affected PHP files until a patch is available. As a temporary workaround, avoid using the blog theme parameter with a .. (dot dot) sequence in the "index.php", "add cgi.php", "add link.php", "login.php", "template.php", or "contact.php" files.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6033

Affected Products

Simple Php Blog