PT-2011-1331 · Cre Loaded · Cre Loaded

CVE-2009-5077

·

Publicado

2011-06-08

·

Atualizado

2024-02-14

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions CRE Loaded versions prior to 6.2.14
Description The issue allows remote attackers to bypass authentication and gain administrator privileges. This is related to a modified PHP SELF variable, which is not properly handled by includes in the application.
Recommendations For versions prior to 6.2.14, update to version 6.2.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the includes/application top.php and admin/includes/application top.php files until a patch is available. Avoid using modified PHP SELF variables in the affected includes until the issue is resolved.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-5077

Produtos afetados

Cre Loaded