| VID |
210030 |
| Severity |
40 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The phpMyFAQ software is vulnerable to multiple vulnerabilities which exist in versions prior to 1.6.8. phpMyFAQ is a freely available FAQ-system that uses a MySQL database for Microsoft Windows operating systems. phpMyFAQ versions prior to 1.6.8 could allow a remote attacker to execute arbitrary SQL commands, caused by improper filtering of user-supplied input passed to the 'uin' parameter of several scripts. In addition, the affected application also could allow a remote attacker to upload arbitrary PHP files and execute arbitrary code on the host.
* References: http://www.phpmyfaq.de/advisory_2006-12-15.php http://www.frsirt.com/english/advisories/2007/0077 http://secunia.com/advisories/23651
* Platforms Affected: Thorsten Rinne, PhpMyFAQ versions prior to 1.6.8 Microsoft Windows Any version |
| Recommendation |
Upgrade to the latest version of phpMyFaq (1.6.8 or later), available from the phpMyFaq Download Web page at http://www.phpmyfaq.de/download.php |
| Related URL |
CVE-2006-6912,CVE-2006-6913 (CVE) |
| Related URL |
21944,21945 (SecurityFocus) |
| Related URL |
31369,31370 (ISS) |
|