EJ3 TOPo Class_DB_Text.PHP Multiple Remote PHP Script Code Injection Vulnerabilities
BID:18935
CVE-2006-3536 |Info
EJ3 TOPo Class_DB_Text.PHP Multiple Remote PHP Script Code Injection Vulnerabilities
| Bugtraq ID: | 18935 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2006 12:00AM |
| Updated: | Jul 13 2006 11:38PM |
| Credit: | Hessam-x is credited with the discovery these vulnerabilities. |
| Vulnerable: |
EJ3 TOPo 2.2.178 |
| Not Vulnerable: | |
Discussion
EJ3 TOPo Class_DB_Text.PHP Multiple Remote PHP Script Code Injection Vulnerabilities
EJ3 TOPo is prone to multiple remote PHP code-injection vulnerabilities.
This issue occurs because the application fails to sanitize user-supplied input before storing it in a PHP file within the data directory.
An attacker can exploit this issue by placing an arbitrary PHP script into the server and then initiate a GET request to execute the PHP within the context of the server.
Versions 2.2.178 and prior are affected.
EJ3 TOPo is prone to multiple remote PHP code-injection vulnerabilities.
This issue occurs because the application fails to sanitize user-supplied input before storing it in a PHP file within the data directory.
An attacker can exploit this issue by placing an arbitrary PHP script into the server and then initiate a GET request to execute the PHP within the context of the server.
Versions 2.2.178 and prior are affected.
Exploit / POC
EJ3 TOPo Class_DB_Text.PHP Multiple Remote PHP Script Code Injection Vulnerabilities
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
EJ3 TOPo Class_DB_Text.PHP Multiple Remote PHP Script Code Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
EJ3 TOPo Class_DB_Text.PHP Multiple Remote PHP Script Code Injection Vulnerabilities
References:
References:
- EJ3 Topo Home Page (EJ3 Soft)