PHPBook Mail Field PHP Code Injection Vulnerability
BID:16106
Info
PHPBook Mail Field PHP Code Injection Vulnerability
| Bugtraq ID: | 16106 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 29 2005 12:00AM |
| Updated: | Dec 29 2005 12:00AM |
| Credit: | Discovery is credited to Aliaksandr Hartsuyeu. |
| Vulnerable: |
phpBook phpBook 1.3.2 phpBook phpBook 1.3 phpBook phpBook 1.2 phpBook phpBook 1.1 phpBook phpBook 1.0 |
| Not Vulnerable: | |
Discussion
PHPBook Mail Field PHP Code Injection Vulnerability
phpBook is prone to a vulnerability that may let remote attackers inject arbitrary PHP code into the application. This code may then be executed by visiting pages that include the injected code.
phpBook is prone to a vulnerability that may let remote attackers inject arbitrary PHP code into the application. This code may then be executed by visiting pages that include the injected code.
Exploit / POC
PHPBook Mail Field PHP Code Injection Vulnerability
The following example was provided:
E-mail field: qwe@<? anyphpcode(); ?>.com
The following example was provided:
E-mail field: qwe@<? anyphpcode(); ?>.com
Solution / Fix
PHPBook Mail Field PHP Code Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
PHPBook Mail Field PHP Code Injection Vulnerability
References:
References:
- phpBook Homepage (phpBook)
- phpBook PHP Code Execution (eVuln)