PT-2007-6065 · Yapig · Yapig
CVE-2007-4951
·
Publicado
2007-09-18
·
Atualizado
2024-08-07
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
YaPiG version 0.95b
Description
A remote file inclusion issue in sample.php allows remote attackers to execute arbitrary PHP code via a URL in the
YAPIG PATH parameter.Recommendations
For YaPiG version 0.95b, consider restricting the use of the
YAPIG PATH parameter to minimize the risk of exploitation.Exploit
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Yapig