PT-2009-2013 · Comscripts Team · Comscripts Team Quick Classifieds

Published

2009-03-30

·

Updated

2017-08-17

·

CVE-2008-6543

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions ComScripts TEAM Quick Classifieds version 1.0
Description The issue affects ComScripts TEAM Quick Classifieds, allowing remote file inclusion via the DOCUMENT ROOT parameter in multiple PHP files. This includes files such as index.php3, locate.php3, search results.php3, and others in various directories, including the root, classifieds, controlcenter, and controlpannel. Additionally, files like include/sendit.php3 and include/sendit2.php3 are affected. Possibly, files such as include/adminHead.inc, include/usersHead.inc, and style/default.scheme.inc are also vulnerable.
Recommendations For ComScripts TEAM Quick Classifieds version 1.0, as a temporary workaround, consider restricting access to the vulnerable PHP files until a patch is available. Avoid using the DOCUMENT ROOT parameter in the affected API endpoints, such as index.php3, locate.php3, and others, until the issue is resolved. Restrict access to the controlcenter and controlpannel directories to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6543

Affected Products

Comscripts Team Quick Classifieds