First published: Tue Aug 18 2009(Updated: )
modules/tool/hitcounter.php in devalcms 1.4a allows remote attackers to execute arbitrary PHP code via the HTTP Referer header with a target file specified in the gv_folder_data parameter, as demonstrated by modifying modules/tool/url2header.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Usualtool CMS | =1.4a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-6983 is considered a high severity vulnerability due to its ability to allow remote code execution.
CVE-2008-6983 can be exploited through the HTTP Referer header by specifying a target file in the gv_folder_data parameter.
To fix CVE-2008-6983, update to a patched version of devalcms or implement input validation to mitigate the risk.
CVE-2008-6983 affects devalcms version 1.4a.
Yes, CVE-2008-6983 can allow unauthorized users to execute arbitrary PHP code on the server.