PT-2008-5950 · Plugspace · Plugspace
Dun
·
Published
2008-10-24
·
Updated
2017-09-29
·
CVE-2008-4739
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PlugSpace version 0.1
Description
The issue allows remote attackers to include and execute arbitrary local files. This is achieved by exploiting a directory traversal vulnerability in the index.php file when the magic quotes gpc setting is disabled. The vulnerability can be triggered by including a .. (dot dot) in the
navi parameter of a specific API endpoint, although the exact endpoint is not specified.Recommendations
For PlugSpace version 0.1, consider disabling the execution of arbitrary local files or restricting access to the
navi parameter until a patch is available. Additionally, enabling magic quotes gpc may help mitigate this issue.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plugspace