PT-2008-6329 · Nigel Mcnie · Geshi
Published
2008-11-21
·
Updated
2024-08-07
·
CVE-2008-5186
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Generic Syntax Highlighter (GeSHi) versions prior to 1.0.8.1
Description
The set language path function in geshi.php might allow remote attackers to conduct file inclusion attacks via crafted inputs that influence the default language path (
$path variable). This issue has been disputed by a vendor, stating that only a static value is used, so this is not a vulnerability in GeSHi. Separate issues would be created for web applications that integrate GeSHi in a way that allows control of the default language path.Recommendations
For versions prior to 1.0.8.1, update to version 1.0.8.1 or later to resolve the issue. As a temporary workaround, consider restricting the influence of crafted inputs on the default language path (
$path variable) to minimize the risk of exploitation.Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Geshi