PT-2006-7062 · J Owamp · J-Owamp Web Interface

Dr Max Virus

·

Published

2006-12-10

·

Updated

2017-10-19

·

CVE-2006-6453

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions J-OWAMP Web Interface version 2.1
Description The issue allows remote authenticated users to execute arbitrary PHP code via a URL in the link parameter in the JOWAMP ShowPage.php file.
Recommendations For J-OWAMP Web Interface version 2.1, consider restricting access to the JOWAMP ShowPage.php file until a patch is available. As a temporary workaround, avoid using the link parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6453

Affected Products

J-Owamp Web Interface