PT-2007-2470 · X News · Xpression News
Published
2007-02-21
·
Updated
2017-07-29
·
CVE-2007-1042
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Xpression News (X-News) version 1.0.1
Description:
A directory traversal issue exists in the news.php file of Xpression News (X-News) when the magic quotes gpc setting is disabled. This allows remote attackers to include arbitrary files or obtain sensitive information by using a .. (dot dot) in the
xnews-template parameter.Recommendations:
For Xpression News (X-News) version 1.0.1, consider disabling the news.php file or restricting access to it until a fix is available. Additionally, enabling the magic quotes gpc setting may help mitigate this issue. Avoid using the
xnews-template parameter with untrusted input until the issue is resolved.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xpression News