PT-2007-6223 · Php+1 · Php+1
Jesper Jurcenoks
·
Published
2007-09-27
·
Updated
2018-10-15
·
CVE-2007-5128
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SimpNews version 2.41.03
Description
The issue allows remote attackers to obtain sensitive information via a certain
link date parameter to "events.php", which reveals the path in an error message due to an unsupported argument type for the mktime function on Windows. This occurs when PHP before version 5.0.0 is used.Recommendations
For SimpNews version 2.41.03, consider updating PHP to version 5.0.0 or later to resolve the issue. As a temporary workaround, restrict access to the "events.php" endpoint to minimize the risk of exploitation. Avoid using the
link date parameter in the affected endpoint until the issue is resolved.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php
Simpnews