PT-2007-3943 · Aiocp · All In One Control Panel

Published

2007-05-11

·

Updated

2017-07-29

·

CVE-2007-2624

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions All In One Control Panel (AIOCP) versions prior to 1.3.016
Description The issue concerns a dynamic variable evaluation vulnerability in the shared/config/cp config.php file. This vulnerability allows remote attackers to conduct cross-site scripting (XSS) and possibly other attacks via the SERVER superglobal array.
Recommendations For versions prior to 1.3.016, update to version 1.3.016 or later to resolve the issue. As a temporary workaround, consider restricting access to the shared/config/cp config.php file to minimize the risk of exploitation. Avoid using the SERVER superglobal array in sensitive operations until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2624

Affected Products

All In One Control Panel