PT-2010-2681 · Tribisur · Tribisur

Cr4Wl3R

·

Published

2010-03-09

·

Updated

2010-03-10

·

CVE-2010-0958

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Tribisur versions 2.1, 2.0, and earlier
Description The issue allows remote attackers to include and execute arbitrary files via directory traversal sequences in the theme parameter when magic quotes gpc is disabled.
Recommendations For Tribisur versions 2.1, 2.0, and earlier, consider disabling the theme parameter in the modules/hayoo/index.php file until a patch is available. Restrict access to the modules/hayoo/index.php file to minimize the risk of exploitation. Enable magic quotes gpc to prevent directory traversal attacks.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-0958

Affected Products

Tribisur