PT-2023-10129 · Unknown · Sternenseemann Sternenblog
Published
2023-01-07
·
Updated
2024-05-17
·
CVE-2014-125059
CVSS v2.0
4.6
Medium
| Vector | AV:N/AC:H/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
sternenseemann sternenblog versions prior to 0.1.0
Description
A problematic issue has been found in sternenseemann sternenblog, affecting the
blog index function of the file main.c. The manipulation of the post path argument leads to file inclusion. The attack can be initiated remotely, with a rather high complexity and difficult exploitation. This case is considered theoretical and unlikely to occur, possibly only on obscure web servers.Recommendations
For versions prior to 0.1.0, upgrade to version 0.1.0 to address this issue. As a temporary workaround, consider restricting access to the
blog index function or the post path argument to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sternenseemann Sternenblog