Admbook Remote PHP Script Code Execution Vulnerability
BID:16753
Info
Admbook Remote PHP Script Code Execution Vulnerability
| Bugtraq ID: | 16753 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 21 2006 12:00AM |
| Updated: | Feb 22 2006 11:12PM |
| Credit: | rgod <[email protected]> is credited with the discovery of this issue. |
| Vulnerable: |
devScripts Admbook 1.2.2 |
| Not Vulnerable: | |
Discussion
Admbook Remote PHP Script Code Execution Vulnerability
Admbook is prone to a remote PHP script code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary malicious PHP code and execute it in the context of the webserver process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Admbook version 1.2.2 is vulnerable to these issues; other versions may also be affected.
Admbook is prone to a remote PHP script code-execution vulnerability.
An attacker can exploit this issue to execute arbitrary malicious PHP code and execute it in the context of the webserver process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Admbook version 1.2.2 is vulnerable to these issues; other versions may also be affected.
Exploit / POC
Admbook Remote PHP Script Code Execution Vulnerability
An exploit is not required.
A sample exploit application by rgod <[email protected]> is available:
An exploit is not required.
A sample exploit application by rgod <[email protected]> is available:
Solution / Fix
Admbook Remote PHP Script Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]