PT-2007-4199 · Navboard · Navboard

Dj7Xpl

·

Published

2007-05-30

·

Updated

2017-10-11

·

CVE-2007-2899

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions NavBoard version 2.6.0
Description A direct static code injection issue exists, allowing remote attackers to inject arbitrary PHP code into data/config.php via multiple parameters. This is demonstrated through the threadperpage parameter in an editconfig action.
Recommendations For NavBoard version 2.6.0, consider restricting access to the admin config.php file and avoid using the threadperpage parameter in the editconfig action until a patch is available. As a temporary workaround, restrict modifications to the data/config.php file to prevent arbitrary code injection.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-2899

Affected Products

Navboard