製品・ソフトウェアに関する情報
Paul M. Jones Savant2 における PHP リモートファイルインクルージョンの脆弱性
Title Paul M. Jones Savant2 における PHP リモートファイルインクルージョンの脆弱性
Summary

Paul M. Jones Savant2 には、Mambo および Joomla! 用の com_mtree コンポーネントと一緒に使用されている際、PHP リモートファイルインクルージョンの脆弱性が存在します。

Possible impacts 第三者により、以下のパラメータの URL を介して、任意の PHP コードを実行される可能性があります。 (1) Savant2_Plugin_stylesheet.php の mosConfig_absolute_path パラメータ (2) Savant2_Compiler_basic.php の mosConfig_absolute_path パラメータ (3) Savant2_Error_pear.php の mosConfig_absolute_path パラメータ (4) Savant2_Error_stack.php の mosConfig_absolute_path パラメータ (5) Savant2_Filter_colorizeCode.php の mosConfig_absolute_path パラメータ (6) Savant2_Filter_trimwhitespace.php の mosConfig_absolute_path パラメータ (7) Savant2_Plugin_ahref.php の mosConfig_absolute_path パラメータ (8) Savant2_Plugin_ahrefcontact.php の mosConfig_absolute_path パラメータ (9) Savant2_Plugin_ahreflisting.php の mosConfig_absolute_path パラメータ (10) Savant2_Plugin_ahreflistingimage.php の mosConfig_absolute_path パラメータ (11) Savant2_Plugin_ahrefmap.php の mosConfig_absolute_path パラメータ (12) Savant2_Plugin_ahrefownerlisting.php の mosConfig_absolute_path パラメータ (13) Savant2_Plugin_ahrefprint.php の mosConfig_absolute_path パラメータ (14) Savant2_Plugin_ahrefrating.php の mosConfig_absolute_path パラメータ (15) Savant2_Plugin_ahrefrecommend.php の mosConfig_absolute_path パラメータ (16) Savant2_Plugin_ahrefreport.php の mosConfig_absolute_path パラメータ (17) Savant2_Plugin_ahrefreview.php の mosConfig_absolute_path パラメータ (18) Savant2_Plugin_ahrefvisit.php の mosConfig_absolute_path パラメータ (19) Savant2_Plugin_checkbox.php の mosConfig_absolute_path パラメータ (20) Savant2_Plugin_cycle.php の mosConfig_absolute_path パラメータ (21) Savant2_Plugin_dateformat.php の mosConfig_absolute_path パラメータ (22) Savant2_Plugin_editor.php の mosConfig_absolute_path パラメータ (23) Savant2_Plugin_form.php の mosConfig_absolute_path パラメータ (24) Savant2_Plugin_image.php の mosConfig_absolute_path パラメータ (25) Savant2_Plugin_input.php の mosConfig_absolute_path パラメータ (26) Savant2_Plugin_javascript.php の mosConfig_absolute_path パラメータ (27) Savant2_Plugin_listalpha.php の mosConfig_absolute_path パラメータ (28) Savant2_Plugin_listingname.php の mosConfig_absolute_path パラメータ (29) Savant2_Plugin_modify.php の mosConfig_absolute_path パラメータ (30) Savant2_Plugin_mtpath.php の mosConfig_absolute_path パラメータ (31) Savant2_Plugin_options.php の mosConfig_absolute_path パラメータ (32) Savant2_Plugin_radios.php の mosConfig_absolute_path パラメータ (33) Savant2_Plugin_rating.php の mosConfig_absolute_path パラメータ (34) Savant2_Plugin_textarea.php の mosConfig_absolute_path パラメータ
Solution

ベンダ情報および参考情報を参照して適切な対策を実施してください。

Publication Date Aug. 4, 2006, midnight
Registration Date Dec. 20, 2012, 6:02 p.m.
Last Update Dec. 20, 2012, 6:02 p.m.
CVSS2.0 : 危険
Score 7.5
Vector AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected System
phpsavant
savant2 
CVE (情報セキュリティ 共通脆弱性識別子)
ベンダー情報
Change Log
No Changed Details Date of change
0 [2012年12月20日]
  掲載
Feb. 17, 2018, 10:37 a.m.

NVD Vulnerability Information
CVE-2006-3990
Summary

Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree component for Mambo and Joomla!, allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) Savant2_Plugin_stylesheet.php, (2) Savant2_Compiler_basic.php, (3) Savant2_Error_pear.php, (4) Savant2_Error_stack.php, (5) Savant2_Filter_colorizeCode.php, (6) Savant2_Filter_trimwhitespace.php, (7) Savant2_Plugin_ahref.php, (8) Savant2_Plugin_ahrefcontact.php, (9) Savant2_Plugin_ahreflisting.php, (10) Savant2_Plugin_ahreflistingimage.php, (11) Savant2_Plugin_ahrefmap.php, (12) Savant2_Plugin_ahrefownerlisting.php, (13) Savant2_Plugin_ahrefprint.php, (14) Savant2_Plugin_ahrefrating.php, (15) Savant2_Plugin_ahrefrecommend.php, (16) Savant2_Plugin_ahrefreport.php, (17) Savant2_Plugin_ahrefreview.php, (18) Savant2_Plugin_ahrefvisit.php, (19) Savant2_Plugin_checkbox.php, (20) Savant2_Plugin_cycle.php, (21) Savant2_Plugin_dateformat.php, (22) Savant2_Plugin_editor.php, (23) Savant2_Plugin_form.php, (24) Savant2_Plugin_image.php, (25) Savant2_Plugin_input.php, (26) Savant2_Plugin_javascript.php, (27) Savant2_Plugin_listalpha.php, (28) Savant2_Plugin_listingname.php, (29) Savant2_Plugin_modify.php, (30) Savant2_Plugin_mtpath.php, (31) Savant2_Plugin_options.php, (32) Savant2_Plugin_radios.php, (33) Savant2_Plugin_rating.php, or (34) Savant2_Plugin_textarea.php.

Publication Date Aug. 5, 2006, 9:04 a.m.
Registration Date Jan. 29, 2021, 3:43 p.m.
Last Update Oct. 18, 2018, 6:32 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:phpsavant:savant2:*:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List