PT-2007-3012 · Clbox · Clbox
Published
2007-03-23
·
Updated
2024-08-07
·
CVE-2007-1631
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
CLBOX version 1.01
Description
A remote file inclusion issue in the signup.php file allows remote attackers to execute arbitrary PHP code via a URL in the
header parameter. However, it's noted that this issue has been disputed by a reliable third party, stating that header is defined through an include file before use.Recommendations
For CLBOX version 1.01, as a temporary workaround, consider restricting access to the vulnerable signup.php file until the issue is resolved. Additionally, review the include file that defines the
header parameter to ensure it is properly secured. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Clbox