Laffer IM.PHP File Include Vulnerability
BID:14264
Info
Laffer IM.PHP File Include Vulnerability
| Bugtraq ID: | 14264 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 14 2005 12:00AM |
| Updated: | Jul 14 2005 12:00AM |
| Credit: | Credit is given to Dimian for the discovery of this vulnerability. |
| Vulnerable: |
Laffer Laffer 0.3.2 .7 Laffer Laffer 0.3.2 .6 |
| Not Vulnerable: |
Laffer Laffer 0.3.2 .8 |
Discussion
Laffer IM.PHP File Include Vulnerability
Laffer is susceptible to a remote PHP file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may exploit this issue to execute arbitrary PHP code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Laffer is susceptible to a remote PHP file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may exploit this issue to execute arbitrary PHP code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Exploit / POC
Laffer IM.PHP File Include Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Laffer IM.PHP File Include Vulnerability
Solution:
Please upgrade to version 0.3.2.8.
Laffer Laffer 0.3.2 .7
Laffer Laffer 0.3.2 .6
Solution:
Please upgrade to version 0.3.2.8.
Laffer Laffer 0.3.2 .7
-
Laffer laffer-0.3.2.8.tgz?download
http://laffer.sourceforge.net/cgi-bin/g.pl?http://prdownloads.sourcefo rge.net/laffer/laffer-0.3.2.8.tgz?download
Laffer Laffer 0.3.2 .6
-
Laffer laffer-0.3.2.8.tgz?download
http://laffer.sourceforge.net/cgi-bin/g.pl?http://prdownloads.sourcefo rge.net/laffer/laffer-0.3.2.8.tgz?download
References
Laffer IM.PHP File Include Vulnerability
References:
References:
- Laffer 0.3.2.8 - security update (Laffer)
- Laffer Web Site (Laffer)