Korean
<< Back
VID 210030
Severity 40
Port 80, ...
Protocol TCP
Class CGI
Detailed Description The phpMyFAQ software is vulnerable to multiple vulnerabilities which exist in versions prior to 1.6.8. phpMyFAQ is a freely available FAQ-system that uses a MySQL database for Microsoft Windows operating systems. phpMyFAQ versions prior to 1.6.8 could allow a remote attacker to execute arbitrary SQL commands, caused by improper filtering of user-supplied input passed to the 'uin' parameter of several scripts. In addition, the affected application also could allow a remote attacker to upload arbitrary PHP files and execute arbitrary code on the host.

* References:
http://www.phpmyfaq.de/advisory_2006-12-15.php
http://www.frsirt.com/english/advisories/2007/0077
http://secunia.com/advisories/23651

* Platforms Affected:
Thorsten Rinne, PhpMyFAQ versions prior to 1.6.8
Microsoft Windows Any version
Recommendation Upgrade to the latest version of phpMyFaq (1.6.8 or later), available from the phpMyFaq Download Web page at http://www.phpmyfaq.de/download.php
Related URL CVE-2006-6912,CVE-2006-6913 (CVE)
Related URL 21944,21945 (SecurityFocus)
Related URL 31369,31370 (ISS)