PT-2008-3937 · Plusphp · Plusphp Short Url Multi-User Script

Dr.Toxic

·

Published

2008-05-28

·

Updated

2017-09-29

·

CVE-2008-2480

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: plusPHP Short URL Multi-User Script version 1.6
Description: The issue allows remote attackers to execute arbitrary PHP code via a URL in the pages dir parameter. This can be achieved by manipulating the pages dir parameter in the plus.php file.
Recommendations: For plusPHP Short URL Multi-User Script version 1.6, consider restricting access to the pages dir parameter to prevent remote file inclusion attacks until a patch is available. Avoid using the pages dir parameter in the affected plus.php file until the issue is resolved.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-2480

Affected Products

Plusphp Short Url Multi-User Script