PT-2006-7231 · Webwork · Webwork

Published

2006-12-18

·

Updated

2011-03-08

·

CVE-2006-6629

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WeBWorK versions prior to 2.3.1
Description The issue arises from an insufficiently restrictive regular expression used to determine valid macro filenames in the lib/WeBWorK/PG/Translator.pm file. This allows attackers to load arbitrary macro files whose names contain specific strings, including dangerousMacros.pl, PG.pl, or IO.pl.
Recommendations For versions prior to 2.3.1, update to version 2.3.1 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6629

Affected Products

Webwork