PT-2008-4655 · Phpizabi · Phpizabi
Inphex
·
Published
2008-07-21
·
Updated
2017-09-29
·
CVE-2008-3239
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
PHPizabi version 0.848b C1 HFP1
Description:
The issue is related to an unrestricted file upload vulnerability. This vulnerability can be exploited by remote attackers to upload and execute arbitrary code. The exploitation involves the
writeLogEntry function and requires register globals to be enabled. Attackers can specify a filename in the CONF[CRON LOGFILE] parameter and provide file contents in the CONF[LOCALE LONG DATE TIME] parameter.Recommendations:
For PHPizabi version 0.848b C1 HFP1, consider disabling the
register globals setting to prevent exploitation. Additionally, restrict access to the writeLogEntry function in system/v cron proc.php until a patch is available. Avoid using the CONF[CRON LOGFILE] and CONF[LOCALE LONG DATE TIME] parameters in a way that could allow arbitrary file uploads.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpizabi