PT-2007-6121 · Streamline · Streamline Php Media Server

Bingza

·

Published

2007-09-20

·

Updated

2017-09-29

·

CVE-2007-5015

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Streamline PHP Media Server version 1.0-beta4
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the sl theme unix path parameter to various PHP files, including 'admin footer.php', 'info footer.php', 'theme footer.php', 'browse footer.php', 'account footer.php', and 'search footer.php' in 'core/theme/includes/'. This vulnerability is only present if the administrator does not follow installation instructions regarding the requirement for .htaccess Limit support.
Recommendations For Streamline PHP Media Server version 1.0-beta4, as a temporary workaround, consider restricting access to the sl theme unix path parameter in the affected PHP files until a patch is available. Ensure that the administrator follows the installation instructions about the requirement for .htaccess Limit support to mitigate the risk of exploitation.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-5015

Affected Products

Streamline Php Media Server