PT-2007-4199 · Navboard · Navboard
Dj7Xpl
·
Published
2007-05-30
·
Updated
2017-10-11
·
CVE-2007-2899
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
NavBoard version 2.6.0
Description
A direct static code injection issue exists, allowing remote attackers to inject arbitrary PHP code into data/config.php via multiple parameters. This is demonstrated through the
threadperpage parameter in an editconfig action.Recommendations
For NavBoard version 2.6.0, consider restricting access to the
admin config.php file and avoid using the threadperpage parameter in the editconfig action until a patch is available. As a temporary workaround, restrict modifications to the data/config.php file to prevent arbitrary code injection.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Navboard