FixVibe
Covered by FixVibehigh

Mkpebi koodu dịpụrụ adịpụ na SPIP site na mkpado Template (CVE-2016-7998)

Ụdị SPIP 3.1.2 na mbụ nwere adịghị ike na onye na-ede template. Ndị na-awakpo akwadoro nwere ike bulite faịlụ HTML nwere mkpado INNCLUDE ma ọ bụ INCLURE arụpụtara iji mebie koodu PHP aka ike na sava ahụ.

CVE-2016-7998CWE-20

Mmetụta

Onye mbuso agha enwetara nwere ike mebie koodu PHP aka ike na sava weebụ dị n'okpuru [S1]. Nke a na-enye ohere maka nbibi sistemu zuru oke, gụnyere mkpochapụ data, mgbanwe ọdịnaya saịtị, yana mmegharị mpụta n'ime ebe nnabata [S1].

Ihe kpatara ya

Ọdịmma dị na SPIP template composer and compiler components [S1]. Sistemu anaghị akwado nke ọma ma ọ bụ mee ka ndenye dị ọcha n'ime mkpado ndebiri mgbe ị na-ahazi faịlụ ebugoro [S1]. Kpọmkwem, onye na-achịkọta ihe na-eji ezighi ezi emepụtara INCLUDE ma ọ bụ mkpado INCLURE n'ime faịlụ HTML [S1]. Mgbe onye mwakpo nwetara faịlụ ndị a ebugoro site na omume valider_xml, a na-ahazi mkpado ọjọọ ndị ahụ, na-eduga na koodu PHP [S1].

Ụdị emetụtara

  • Ụdị SPIP 3.1.2 na ụdị mbụ niile [S1].

Mgbanwe

Melite SPIP na ụdị dị ọhụrụ karịa 3.1.2 iji lebara adịghị ike a [S1]. Gbaa mbọ hụ na ikike bulite faịlụ bụ naanị maka ndị ọrụ nhazi ntụkwasị obi yana echekwara faịlụ ebugoro na akwụkwọ ndekọ aha ebe sava weebụ nwere ike igbu ya dị ka script [S1].

Kedu ka FixVibe si nwalee ya

FixVibe nwere ike ịchọpụta adịghị ike a site na ụzọ abụọ bụ isi:

  • Mbipụta mkpịsị aka na-agafe agafe: Site n'ịtụle isi okwu nzaghachi HTTP ma ọ bụ mkpado meta kpọmkwem na isi HTML, FixVibe nwere ike ịchọpụta ụdị agba ọsọ nke SPIP [S1]. Ọ bụrụ na ụdị ahụ bụ 3.1.2 ma ọ bụ dị ala, ọ ga-akpalite ọkwa dị elu [S1].
  • Nyochaa ebe nchekwa: Maka ndị ọrụ na-ejikọta ebe nchekwa GitHub ha, nyocha repo FixVibe nwere ike nyochaa faịlụ ndabere ma ọ bụ nsụgharị na-akọwapụta ihe na-agbanwe agbanwe na koodu isi SPIP iji chọpụta nrụnye adịghị ike ZXCV.