PT-2006-6956 · Neocrome · Neocrome Seditio
Published
2006-12-07
·
Updated
2011-03-08
·
CVE-2006-6344
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Neocrome Seditio versions 1.10 and earlier
Description
The issue is related to multiple unspecified vulnerabilities with unknown impact and attack vectors. These vulnerabilities are associated with several files, including
plugins/ipsearch/ipsearch.admin.php, pfs/pfs.edit.inc.php, and users/users.register.inc.php in system/core. It is noted that one of the vectors might be related to SQL injection, but the specifics are not provided.Recommendations
For Neocrome Seditio versions 1.10 and earlier, consider restricting access to the vulnerable files
ipsearch.admin.php, pfs.edit.inc.php, and users.register.inc.php to minimize the risk of exploitation. Avoid using potentially vulnerable functions or parameters in these files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Neocrome Seditio