PT-2008-6631 · Php · Php Multiple Newsletters
Ahmadbady
·
Published
2008-12-15
·
Updated
2017-09-29
·
CVE-2008-5570
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PHP Multiple Newsletters version 2.7
Description
A directory traversal issue exists in index.php, allowing remote attackers to include and execute arbitrary local files when magic quotes gpc is disabled. This is achieved by using a .. (dot dot) in the
lang parameter.Recommendations
For PHP Multiple Newsletters version 2.7, consider enabling magic quotes gpc to prevent the exploitation of this issue. As a temporary workaround, restrict access to the
lang parameter in the index.php file to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Php Multiple Newsletters