PT-2008-3937 · Plusphp · Plusphp Short Url Multi-User Script
Dr.Toxic
·
Published
2008-05-28
·
Updated
2017-09-29
·
CVE-2008-2480
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
plusPHP Short URL Multi-User Script version 1.6
Description:
The issue allows remote attackers to execute arbitrary PHP code via a URL in the
pages dir parameter. This can be achieved by manipulating the pages dir parameter in the plus.php file.Recommendations:
For plusPHP Short URL Multi-User Script version 1.6, consider restricting access to the
pages dir parameter to prevent remote file inclusion attacks until a patch is available. Avoid using the pages dir parameter in the affected plus.php file until the issue is resolved.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plusphp Short Url Multi-User Script