PT-2010-2779 · Phpkobo · Phpkobo Address Book Script

Pouya Daneshmand

·

Published

2010-03-23

·

Updated

2017-08-17

·

CVE-2010-1058

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Phpkobo Address Book Script version 1.09
Description The issue allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the LANG CODE parameter when magic quotes gpc is disabled. This is a directory traversal vulnerability in the codelib/cfg/common.inc.php file.
Recommendations For Phpkobo Address Book Script version 1.09, consider disabling the use of the LANG CODE parameter until a patch is available, or enable magic quotes gpc to prevent the exploitation of this issue.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1058

Affected Products

Phpkobo Address Book Script