|
|
Info |
Last Modified |
| 8 months ago |
|
|
|
|
Description |
Hermes contains a flaw that may allow a malicious user to compromise a vulnerable system. The issue is triggered when arbitrary scripts are included in Hermes operation. It is possible that the flaw may allow execution of arbitrary script code resulting in a loss of integrity.
|
|
Classification |
Unknown or Incomplete
|
|
Technical |
Hermes CRM 0.3.0-Alpha-4 and lower are vulnerable if both the 'allow_url_fopen' and 'register_globals' PHP directives are enabled.
|
|
Solution |
Upgrade to version 0.3.0 beta 1 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround(s): Disable the 'allow_url_fopen' and 'register_globals' PHP directives, doing this may break functionality.
|
|
Products |
|
CRM
 |
0.3.0-Alpha-4 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|