PT-2010-2784 · Phpkobo · Phpkobo Free Real Estate Contact Form

Published

2010-03-23

·

Updated

2010-03-24

·

CVE-2010-1063

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Phpkobo Free Real Estate Contact Form version 1.09
Description The issue allows remote attackers to include and execute arbitrary local files via directory traversal sequences when magic quotes gpc is disabled. This can be achieved by manipulating the LANG CODE parameter in specific API endpoints, such as /codelib/cfg/common.inc.php, /form/app/common.inc.php, and /staff/app/common.inc.php.
Recommendations For Phpkobo Free Real Estate Contact Form version 1.09, consider disabling the execution of files from the codelib/cfg, form/app, and staff/app directories until a patch is available. Restrict access to the LANG CODE parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2010-1063

Affected Products

Phpkobo Free Real Estate Contact Form