PT-2023-10129 · Unknown · Sternenseemann Sternenblog

Published

2023-01-07

·

Updated

2024-05-17

·

CVE-2014-125059

CVSS v2.0

4.6

Medium

VectorAV:N/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions sternenseemann sternenblog versions prior to 0.1.0
Description A problematic issue has been found in sternenseemann sternenblog, affecting the blog index function of the file main.c. The manipulation of the post path argument leads to file inclusion. The attack can be initiated remotely, with a rather high complexity and difficult exploitation. This case is considered theoretical and unlikely to occur, possibly only on obscure web servers.
Recommendations For versions prior to 0.1.0, upgrade to version 0.1.0 to address this issue. As a temporary workaround, consider restricting access to the blog index function or the post path argument to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2014-125059

Affected Products

Sternenseemann Sternenblog