PT-2007-2208 · Php · Phpprobid
Published
2007-02-06
·
Updated
2017-07-29
·
CVE-2007-0758
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHPProbid version 5.24
Description
A remote file inclusion issue exists in the lang.php file of PHPProbid, allowing remote attackers to execute arbitrary PHP code. This is achieved by providing a URL in the SRC attribute of an HTML element within the
lang parameter.Recommendations
For PHPProbid version 5.24, consider restricting access to the lang.php file to prevent remote file inclusion attacks. As a temporary workaround, avoid using the
lang parameter in URLs until a patch is available.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpprobid