PHPShop Remote PHP Script Execution Vulnerability
BID:10313
Info
PHPShop Remote PHP Script Execution Vulnerability
| Bugtraq ID: | 10313 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2004 12:00AM |
| Updated: | May 10 2004 12:00AM |
| Credit: | This issue was discovered by "Calum Power" <[email protected]>. |
| Vulnerable: |
phpShop Web Shopping Cart 0.7.1 phpShop Web Shopping Cart 0.7 phpShop Web Shopping Cart 0.6.1 -b |
| Not Vulnerable: | |
Discussion
PHPShop Remote PHP Script Execution Vulnerability
Reportedly phpShop is affected by a remote PHP script execution vulnerability. This issue is due to improper validation of user-supplied variables passed to the application via URI, POST or COOKIE parameters.
This issue is present whether or not the PHP Apache module is configured with 'register_globals' turned off or on.
This issue would allow an attacker to execute arbitrary PHP scripts on an affected host; issuing commands to the underlying operating system with the privileges of the web server is possible.
Reportedly phpShop is affected by a remote PHP script execution vulnerability. This issue is due to improper validation of user-supplied variables passed to the application via URI, POST or COOKIE parameters.
This issue is present whether or not the PHP Apache module is configured with 'register_globals' turned off or on.
This issue would allow an attacker to execute arbitrary PHP scripts on an affected host; issuing commands to the underlying operating system with the privileges of the web server is possible.
Exploit / POC
PHPShop Remote PHP Script Execution Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
PHPShop Remote PHP Script Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPShop Remote PHP Script Execution Vulnerability
References:
References:
- Product Homepage (phpShop)
- Arbitrary code inclusion in phpShop ("Calum Power"
)