PT-2010-2782 · Phpkobo · Phpkobo Short Url
Published
2010-03-23
·
Updated
2010-03-24
·
CVE-2010-1061
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Phpkobo Short URL version 1.01
Description
The issue allows remote attackers to include and execute arbitrary local files via directory traversal sequences when
magic quotes gpc is disabled. This is achieved by manipulating the LANG CODE parameter in API endpoints such as "url/app/common.inc.php" and "codelib/cfg/common.inc.php".Recommendations
For Phpkobo Short URL version 1.01, consider disabling the execution of files from arbitrary locations until a patch is available. Restrict access to the
url/app/common.inc.php and codelib/cfg/common.inc.php files to minimize the risk of exploitation. Avoid using the LANG CODE parameter in the affected API endpoints until the issue is resolved. Enable magic quotes gpc to prevent directory traversal attacks.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpkobo Short Url