PT-2009-4548 · Mundi · Mundi Mail

Br0Ly

·

Published

2009-06-17

·

Updated

2017-09-29

·

CVE-2009-2095

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mundi Mail version 0.8.2
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the top parameter when register globals is enabled. If allow url fopen is disabled, it is possible to perform directory traversal attacks to include and execute arbitrary local files.
Recommendations For Mundi Mail version 0.8.2, consider disabling the register globals setting to prevent remote code execution. Additionally, enable allow url fopen to prevent directory traversal attacks, or restrict access to the template/simpledefault/admin/ masterlayout.php file to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2095

Affected Products

Mundi Mail