Jinzora Include_Path Remote File Include Vulnerability
BID:14188
Info
Jinzora Include_Path Remote File Include Vulnerability
| Bugtraq ID: | 14188 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2005 12:00AM |
| Updated: | Jul 07 2005 12:00AM |
| Credit: | The vendor is credited with the discovery of this vulnerability. |
| Vulnerable: |
Jinzora Jinzora 2.0.1 |
| Not Vulnerable: |
Jinzora Jinzora 2.1 |
Discussion
Jinzora Include_Path Remote File Include Vulnerability
Jinzora is susceptible to a remote file include vulnerability, due to lack of validation of the 'include_path' variable.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Jinzora is susceptible to a remote file include vulnerability, due to lack of validation of the 'include_path' variable.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Exploit / POC
Jinzora Include_Path Remote File Include Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Jinzora Include_Path Remote File Include Vulnerability
Solution:
The vendor has addressed this issue in Jinzora version 2.1.
Jinzora Jinzora 2.0.1
Solution:
The vendor has addressed this issue in Jinzora version 2.1.
Jinzora Jinzora 2.0.1
-
Jinzora j2.1.tar.gz
http://www.jinzora.com/downloads/j2.1.tar.gz