AnyPortal(PHP) Siteman.PHP3 Directory Traversal Vulnerability
BID:17197
Info
AnyPortal(PHP) Siteman.PHP3 Directory Traversal Vulnerability
| Bugtraq ID: | 17197 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 24 2003 12:00AM |
| Updated: | Mar 22 2006 09:19PM |
| Credit: | Nuno Justo is credited with the discovery of this vulnerability. |
| Vulnerable: |
AnyPortal(php) AnyPortal(php) 12 MAY 00 |
| Not Vulnerable: | |
Discussion
AnyPortal(PHP) Siteman.PHP3 Directory Traversal Vulnerability
AnyPortal(php) is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to overwrite or delete arbitrary files on the vulnerable computer in the context of the webserver process.
AnyPortal(php) is prone to a directory-traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to overwrite or delete arbitrary files on the vulnerable computer in the context of the webserver process.
Exploit / POC
AnyPortal(PHP) Siteman.PHP3 Directory Traversal Vulnerability
This issue can be exploited through use of a web client.
This issue can be exploited through use of a web client.
Solution / Fix
AnyPortal(PHP) Siteman.PHP3 Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
AnyPortal(PHP) Siteman.PHP3 Directory Traversal Vulnerability
References:
References:
- AnyPortal(php) Homepage (AnyPortal(php))
- MAJOR SECURITY BUGS FOUND (Nuno Justo)