PT-2007-1166 · Unknown · G/Pgp Plugin

Published

2007-07-15

·

Updated

2017-07-20

·

CVE-2006-4169

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: G/PGP (GPG) Plugin versions 2.0 through 2.1dev before 20070614
Description: The issue allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the help parameter to API endpoints such as "gpg help.php" or "gpg help base.php".
Recommendations: For G/PGP (GPG) Plugin versions 2.0 through 2.1dev before 20070614, consider updating to a version released after 20070614 to resolve the issue. As a temporary workaround, restrict access to the "gpg help.php" and "gpg help base.php" files to minimize the risk of exploitation. Avoid using the help parameter in the affected API endpoints until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4169

Affected Products

G/Pgp Plugin