PT-2010-2778 · Phpkobo · Phpkobo Adfreely

Ahmadbady

·

Published

2010-03-23

·

Updated

2017-08-17

·

CVE-2010-1057

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Phpkobo AdFreely (aka Ad Board Script) version 1.01
Description The issue allows remote attackers to include and execute arbitrary local files via a ..// (dot dot slash slash) in the LANG CODE parameter to various files, including common.inc.php in multiple directories such as codelib/cfg/, codelib/sys/, staff/, staff/app/, and staff/file.php, when magic quotes gpc is disabled.
Recommendations For Phpkobo AdFreely (aka Ad Board Script) version 1.01, consider disabling the LANG CODE parameter in the affected files until a patch is available. Restrict access to the common.inc.php file in the mentioned directories to minimize the risk of exploitation. Additionally, enable magic quotes gpc to prevent this type of attack.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1057

Affected Products

Phpkobo Adfreely