PT-2006-6956 · Neocrome · Neocrome Seditio

Published

2006-12-07

·

Updated

2011-03-08

·

CVE-2006-6344

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Neocrome Seditio versions 1.10 and earlier
Description The issue is related to multiple unspecified vulnerabilities with unknown impact and attack vectors. These vulnerabilities are associated with several files, including plugins/ipsearch/ipsearch.admin.php, pfs/pfs.edit.inc.php, and users/users.register.inc.php in system/core. It is noted that one of the vectors might be related to SQL injection, but the specifics are not provided.
Recommendations For Neocrome Seditio versions 1.10 and earlier, consider restricting access to the vulnerable files ipsearch.admin.php, pfs.edit.inc.php, and users.register.inc.php to minimize the risk of exploitation. Avoid using potentially vulnerable functions or parameters in these files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6344

Affected Products

Neocrome Seditio