PT-2007-4163 · Simpgb · Simpgb

Published

2007-05-24

·

Updated

2024-02-14

·

CVE-2007-2859

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SimpGB version 1.46.0
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the path simpgb parameter to various PHP scripts, including "guestbook.php", "search.php", "mailer.php", "avatars.php", "ccode.php", "comments.php", "emoticons.php", and "gbdownload.php".
Recommendations For SimpGB version 1.46.0, consider restricting access to the path simpgb parameter in the affected PHP scripts until a patch is available. As a temporary workaround, avoid using the path simpgb parameter in the vulnerable API endpoints.

Fix

Related Identifiers

CVE-2007-2859

Affected Products

Simpgb