PT-2007-5010 · Psnews · Psnews

Irk4Z

·

Published

2007-07-15

·

Updated

2017-09-29

·

CVE-2007-3772

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions PsNews version 1.1
Description A directory traversal issue exists, allowing remote attackers to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the newspath parameter.
Recommendations For PsNews version 1.1, consider restricting access to the news/show.php file until a patch is available, or avoid using the newspath parameter with untrusted input to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3772

Affected Products

Psnews