PT-2009-2013 · Comscripts Team · Comscripts Team Quick Classifieds
Published
2009-03-30
·
Updated
2017-08-17
·
CVE-2008-6543
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
ComScripts TEAM Quick Classifieds version 1.0
Description
The issue affects ComScripts TEAM Quick Classifieds, allowing remote file inclusion via the
DOCUMENT ROOT parameter in multiple PHP files. This includes files such as index.php3, locate.php3, search results.php3, and others in various directories, including the root, classifieds, controlcenter, and controlpannel. Additionally, files like include/sendit.php3 and include/sendit2.php3 are affected. Possibly, files such as include/adminHead.inc, include/usersHead.inc, and style/default.scheme.inc are also vulnerable.Recommendations
For ComScripts TEAM Quick Classifieds version 1.0, as a temporary workaround, consider restricting access to the vulnerable PHP files until a patch is available. Avoid using the
DOCUMENT ROOT parameter in the affected API endpoints, such as index.php3, locate.php3, and others, until the issue is resolved. Restrict access to the controlcenter and controlpannel directories to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Comscripts Team Quick Classifieds