PT-2007-4163 · Simpgb · Simpgb

CVE-2007-2859

·

Publicado

2007-05-24

·

Atualizado

2024-02-14

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SimpGB version 1.46.0
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the path simpgb parameter to various PHP scripts, including "guestbook.php", "search.php", "mailer.php", "avatars.php", "ccode.php", "comments.php", "emoticons.php", and "gbdownload.php".
Recommendations For SimpGB version 1.46.0, consider restricting access to the path simpgb parameter in the affected PHP scripts until a patch is available. As a temporary workaround, avoid using the path simpgb parameter in the vulnerable API endpoints.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-2859

Produtos afetados

Simpgb