First published: Wed May 06 2009(Updated: )
Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) qte_web_path parameter to qte_web.php and the (2) qte_root parameter to bin/qte_init.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Qt | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1551 is considered to have high severity due to its potential for remote code execution.
To address CVE-2009-1551, update to the latest version of Qt Quickteam that patches these vulnerabilities.
The potential impacts of CVE-2009-1551 include unauthorized remote execution of PHP code and possible compromise of the affected system.
CVE-2009-1551 affects version 2.0 of Qt Quickteam.
The qte_web_path parameter to qte_web.php and the qte_root parameter to bin/qte_init.php are the specific vulnerable parameters in CVE-2009-1551.