PT-2007-1331 · Dotwidget · Dotwidget For Articles

Sweet-Devil

·

Published

2007-02-24

·

Updated

2017-07-29

·

CVE-2006-7052

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DotWidget For Articles (dotwidgeta) version 0.2
Description The issue allows remote attackers to execute arbitrary code via specific parameters in various PHP files. This is achieved by providing a URL in the file path parameter to files such as "index.php", "showcatpicks.php", and "showarticle.php". Additionally, attackers can exploit the admin header file and admin footer file parameters in files like "admin/authors.php", "admin/index.php", "admin/categories.php", "admin/editconfig.php", and "admin/articles.php".
Recommendations For DotWidget For Articles (dotwidgeta) version 0.2, consider disabling the file path, admin header file, and admin footer file parameters in the affected PHP files until a patch is available. Restrict access to the vulnerable PHP files to minimize the risk of exploitation. Avoid using the file path, admin header file, and admin footer file parameters in the affected API endpoints until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7052

Affected Products

Dotwidget For Articles