PT-2009-2960 · Web//News · Wb News

Published

2009-01-27

·

Updated

2018-10-11

·

CVE-2009-0294

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WB News version 2.0.1
Description The issue allows remote attackers to execute arbitrary PHP code when register globals is enabled. This is achieved by providing a URL in the config[installdir] parameter to various PHP files, including "search.php", "archive.php", "comments.php", and "news.php", as well as "News.php", "SendFriend.php", "Archive.php", and "Comments.php" in the base directory. The estimated number of potentially affected devices and details about real-world incidents are not specified.
Recommendations For WB News version 2.0.1, consider disabling the config[installdir] parameter or restricting access to the mentioned PHP files until a patch is available. Additionally, disabling register globals can help mitigate the risk of exploitation. Avoid using the config[installdir] parameter in the affected API endpoints, such as "search.php", "archive.php", "comments.php", and "news.php", as well as "News.php", "SendFriend.php", "Archive.php", and "Comments.php" in the base directory, until the issue is resolved.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0294

Affected Products

Wb News