PT-2007-3987 · Php · Phpchain
Published
2007-05-14
·
Updated
2017-07-29
·
CVE-2007-2670
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
PHPChain versions 1.0 and earlier
Description
The issue allows remote attackers to obtain the installation path by providing invalid values for the
catid parameter to settings.php or cat.php, which can be exploited for XSS manipulations.Recommendations
For PHPChain versions 1.0 and earlier, consider restricting access to the settings.php and cat.php files until a fix is available, and avoid using the
catid parameter in these files to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phpchain