PT-2007-1410 · Phpmydesk · Phpmydesk

Kw3[R]Ln

·

Published

2007-03-06

·

Updated

2017-10-11

·

CVE-2006-7132

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PHPMyDesk version 1.0beta
Description A directory traversal issue exists, allowing remote attackers to include arbitrary local files. This is achieved by manipulating the pmdlang parameter in the "viewticket.php" endpoint.
Recommendations For PHPMyDesk version 1.0beta, as a temporary workaround, consider restricting access to the viewticket.php endpoint until a patch is available. Additionally, avoid using the pmdlang parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-7132

Affected Products

Phpmydesk