PT-2007-5375 · Pluck · Pluck

CVE-2007-4180

·

Publicado

2007-08-08

·

Atualizado

2024-08-07

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pluck version 4.3
Description The issue allows remote attackers to potentially read arbitrary local files via a .. (dot dot) in the file parameter in the data/inc/theme.php file when register globals is enabled. However, it's noted that the code uses a fixed argument when invoking fputs, which cannot be used to read files, thus disputing the vulnerability.
Recommendations For Pluck version 4.3, consider disabling the register globals setting to minimize potential risks, as the vulnerability is contingent upon this setting being enabled. Additionally, restrict access to the data/inc/theme.php file to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-4180

Produtos afetados

Pluck