VID |
210030 |
Severity |
40 |
Port |
80, ... |
Protocol |
TCP |
Class |
CGI |
Detailed Description |
The phpMyFAQ software is vulnerable to multiple vulnerabilities which exist in versions prior to 1.6.8. phpMyFAQ is a freely available FAQ-system that uses a MySQL database for Microsoft Windows operating systems. phpMyFAQ versions prior to 1.6.8 could allow a remote attacker to execute arbitrary SQL commands, caused by improper filtering of user-supplied input passed to the 'uin' parameter of several scripts. In addition, the affected application also could allow a remote attacker to upload arbitrary PHP files and execute arbitrary code on the host.
* References: http://www.phpmyfaq.de/advisory_2006-12-15.php http://www.frsirt.com/english/advisories/2007/0077 http://secunia.com/advisories/23651
* Platforms Affected: Thorsten Rinne, PhpMyFAQ versions prior to 1.6.8 Microsoft Windows Any version |
Recommendation |
Upgrade to the latest version of phpMyFaq (1.6.8 or later), available from the phpMyFaq Download Web page at http://www.phpmyfaq.de/download.php |
Related URL |
CVE-2006-6912,CVE-2006-6913 (CVE) |
Related URL |
21944,21945 (SecurityFocus) |
Related URL |
31369,31370 (ISS) |
|