PT-2007-6641 · Peopleaggregator · Peopleaggregator
Gold_M
·
Published
2007-10-23
·
Updated
2018-10-15
·
CVE-2007-5631
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PeopleAggregator version 1.2pre6
Description
The issue allows remote attackers to execute arbitrary PHP code when register globals is enabled. This is achieved by providing a URL in the
current blockmodule path parameter to various PHP files, including AudiosMediaGalleryModule/AudiosMediaGalleryModule.php, ImagesMediaGalleryModule/ImagesMediaGalleryModule.php, MembersFacewallModule/MembersFacewallModule.php, NewestGroupsModule/NewestGroupsModule.php, UploadMediaModule/UploadMediaModule.php, and VideosMediaGalleryModule/VideosMediaGalleryModule.php in BetaBlockModules/. Additionally, the path prefix parameter in several components is vulnerable.Recommendations
For PeopleAggregator version 1.2pre6, consider disabling the
register globals setting to prevent exploitation. As a temporary workaround, restrict access to the vulnerable PHP files in BetaBlockModules/ and avoid using the current blockmodule path and path prefix parameters in affected components until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Peopleaggregator