FixVibe
Covered by FixVibehigh

Ukwenziwa Kwekhodi Ekude ku-SPIP ngamathegi Wesifanekiso (CVE-2016-7998)

Izinguqulo ze-SPIP 3.1.2 nangaphambili ziqukethe ubungozi kumqambi wesifanekiso. Abahlaseli abagunyaziwe bangalayisha amafayela e-HTML anamathegi acatshangelwe okuthi INCLUDE noma INCLURE ukuze basebenzise ikhodi ye-PHP engafanele kuseva.

CVE-2016-7998CWE-20

Umthelela

Umhlaseli ogunyaziwe angasebenzisa ikhodi ye-PHP engafanele kuseva yewebhu engaphansi [S1]. Lokhu kuvumela ukufakwa engozini okuphelele kwesistimu, okuhlanganisa ukukhishwa kwedatha, ukuguqulwa kokuqukethwe kwesayithi, nokunyakaza okuhlangene ngaphakathi kwendawo yokubamba [S1].

Imbangela

Ubungozi bukhona kumqambi wesifanekiso se-SPIP nezingxenye zenhlanganisela [S1]. Isistimu ihluleka ukuqinisekisa ngokufanelekile noma ukuhlanza okokufaka phakathi komaka bezifanekiso ezithile lapho kucutshungulwa amafayela alayishiwe [S1]. Ngokucacile, isihlanganisi siphatha ngokungalungile omaka abaklanywe benziwe be-INCLUDE noma be-INCLURE ngaphakathi kwamafayela e-HTML [S1]. Uma umhlaseli efinyelela lawa mafayela alayishiwe ngesenzo se-valider_xml, omaka abayingozi bayacutshungulwa, okuholela ekusebenziseni ikhodi ye-PHP [S1].

Izinguqulo Ezithintekile

  • Izinguqulo ze-SPIP 3.1.2 kanye nazo zonke izinguqulo zangaphambili [S1].

Ukulungiswa

Buyekeza i-SPIP ibe inguqulo entsha kuno-3.1.2 ukuze ubhekane nalokhu kuba sengozini [S1]. Qinisekisa ukuthi izimvume zokulayishwa kwefayela zikhawulelwe ngokuqinile kubasebenzisi abaphethe abathenjwayo nokuthi amafayela alayishiwe awagcinwa kunkhombandlela lapho iseva yewebhu ingakwazi ukuwasebenzisa njengemibhalo [S1].

I-FixVibe iyihlolela kanjani

I-FixVibe ingathola lobu bungozi ngokusebenzisa izindlela ezimbili eziyinhloko:

  • Izigxivizo Zeminwe Eziqhubekayo: Ngokuhlaziya izihloko zempendulo ye-HTTP noma ama-meta tag athile kumthombo we-HTML, i-FixVibe ingakwazi ukuhlonza inguqulo esebenzayo ye-SPIP [S1]. Uma inguqulo ithi 3.1.2 noma ngaphansi, izocupha isixwayiso sokuqina okuphezulu [S1].
  • Ukuskena Kwenqolobane: Kubasebenzisi abaxhuma amakhosombe abo e-GitHub, isithwebuli se-repo se-FixVibe singahlola amafayela okuncika noma okufana nokuchaza inguqulo okungaguquki kukhodi yomthombo we-SPIP ukuze kuhlonzwe ukufakwa okusengozini [S1].