Simplicity oF Upload Download.PHP Remote File Include Vulnerability
BID:14424
Info
Simplicity oF Upload Download.PHP Remote File Include Vulnerability
| Bugtraq ID: | 14424 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 29 2005 12:00AM |
| Updated: | Jul 29 2005 12:00AM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
PHPSimplicity Simplicity oF Upload 1.3 |
| Not Vulnerable: |
PHPSimplicity Simplicity oF Upload 1.3.1 |
Discussion
Simplicity oF Upload Download.PHP Remote File Include Vulnerability
Simplicity oF Upload is susceptible to a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may exploit this issue to execute arbitrary PHP code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Simplicity oF Upload is susceptible to a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may exploit this issue to execute arbitrary PHP code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Exploit / POC
Simplicity oF Upload Download.PHP Remote File Include Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Simplicity oF Upload Download.PHP Remote File Include Vulnerability
Solution:
The vendor has addressed this issue in version 1.3.1 of the application:
PHPSimplicity Simplicity oF Upload 1.3
Solution:
The vendor has addressed this issue in version 1.3.1 of the application:
PHPSimplicity Simplicity oF Upload 1.3
-
PHPSimplicity Simplicity oF Upload 1.3.1
http://www.phpsimplicity.com/downloads.php?scriptID=3
References
Simplicity oF Upload Download.PHP Remote File Include Vulnerability
References:
References: