PT-2007-3016 · Npds · Net Portal Dynamic System
Published
2007-03-23
·
Updated
2018-10-16
·
CVE-2007-1635
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Net Portal Dynamic System (NPDS) versions 5.10 and earlier
Description:
The issue allows remote authenticated users to inject arbitrary PHP code via the
xtop parameter in a "ConfigSave" operation to "admin.php", which can later be accessed via a "Configure" operation to "admin.php".Recommendations:
For Net Portal Dynamic System (NPDS) versions 5.10 and earlier, consider restricting access to the "admin.php" endpoint and the
xtop parameter to minimize the risk of exploitation until a fix is available. Avoid using the xtop parameter in the "ConfigSave" operation to "admin.php" until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Net Portal Dynamic System