Changes between Initial Version and Version 1 of Ticket #195
- Timestamp:
- 03/13/08 02:23:41 (17 years ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
Ticket #195 – Description
initial v1 6 6 7 7 8 Details 9 ======= 8 == Details == 10 9 11 10 Product: Mapbender … … 22 21 23 22 24 Introduction 25 ============ 23 == Introduction == 26 24 27 25 "Mapbender is the software and portal site for geodata management of OGC … … 37 35 38 36 39 More Details 40 ============ 37 == More Details == 41 38 42 39 The Mapbender software comes with a script mapFiler.php, which is … … 51 48 52 49 53 Proof of Concept 54 ================ 50 == Proof of Concept == 55 51 56 52 For this example, the user account which is used to execute php scripts … … 90 86 91 87 92 Workaround 93 ========== 88 == Workaround == 94 89 95 90 If not needed, the mapfiler.php script can be removed. Otherwise, it can … … 97 92 98 93 99 Fix 100 === 94 == Fix == 101 95 102 96 The vulnerability is fixed in release 2.4.5 rc1. 103 97 104 98 105 Security Risk 106 ============= 99 == Security Risk == 107 100 108 101 The security risk is rated as high. An attacker can execute arbitrary … … 110 103 111 104 112 History 113 ======= 105 == History == 114 106 115 107 2007-12-14 Problem identified during a penetration test … … 120 112 121 113 122 RedTeam Pentesting GmbH 123 ======================= 114 == RedTeam Pentesting GmbH == 124 115 125 116 RedTeam Pentesting is offering individual penetration tests, short