PHPAccounts Index.PHP Local File Include Vulnerability
BID:24572
Info
PHPAccounts Index.PHP Local File Include Vulnerability
| Bugtraq ID: | 24572 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3346 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 21 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | r0t is credited with the discovery of this vulnerability. |
| Vulnerable: |
PHPAccounts PHPAccounts 0.5 |
| Not Vulnerable: |
PHPAccounts PHPAccounts 0.5.2 |
Discussion
PHPAccounts Index.PHP Local File Include Vulnerability
PHP Accounts is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an unauthorized user to view files and execute local scripts.
PHP Accounts 0.5 is vulnerable; other versions may also be affected.
PHP Accounts is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an unauthorized user to view files and execute local scripts.
PHP Accounts 0.5 is vulnerable; other versions may also be affected.
Exploit / POC
PHPAccounts Index.PHP Local File Include Vulnerability
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/index.php?page=../../etc/passwd
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/index.php?page=../../etc/passwd
Solution / Fix
PHPAccounts Index.PHP Local File Include Vulnerability
Solution:
The vendor has addressed this issue in PHP Accounts 0.5.2. Please see the vendor reference for more information.
PHPAccounts PHPAccounts 0.5
Solution:
The vendor has addressed this issue in PHP Accounts 0.5.2. Please see the vendor reference for more information.
PHPAccounts PHPAccounts 0.5
-
PHPAccounts PHPAccounts 0.5.2
http://trac.phpaccounts.com/browser/tags/0.5.2/index.php?format=raw