Rewterz

Rewterz Threat Advisory – CVE-2020-4631 – IBM Spectrum Protect Plus

August 5, 2020
Rewterz

Rewterz Threat Alert – New njRAT Injection Chain

August 5, 2020

Rewterz Threat Advisory – CVE-2020-5616 – Multiple PHP Factory products security bypass

Severity

Medium

Analysis Summary

Multiple PHP Factory products could allow a remote attacker to bypass security restrictions. By sending a specially-crafted request, an attacker could exploit this vulnerability to log in to the product with administrative privileges.

Impact

Security bypass

Affected Vendors

PHP

Affected Products

  • PHP Factory Calendar01 1.0.0
  • PHP Factory Calendar02 1.0.0
  • PHP Factory PKOBO-News01 1.0.3
  • PHP Factory PKOBO-Vote01 1.0.1
  • HP Factory Telop01 1.0.0
  • PHP Factory Gallery01 1.0.3
  • PHP Factory CalendarForm01 1.0.3
  • PHP Factory Link01 1.0.0

Remediation

Refer to the PHP Factory Web site for patch, upgrade or suggested workaround information.

https://php-factory.net/

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.