PluXML Images.PHP Remote Code Execution Vulnerability
BID:24607
Info
PluXML Images.PHP Remote Code Execution Vulnerability
| Bugtraq ID: | 24607 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 25 2007 12:00AM |
| Updated: | Jun 25 2007 08:18PM |
| Credit: | darkfig is credited with discovering this vulnerability. |
| Vulnerable: |
Pluxml Pluxml 0.3.1 |
| Not Vulnerable: | |
Discussion
PluXML Images.PHP Remote Code Execution Vulnerability
Pluxml is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
Pluxml 0.3.1 is vulnerable to this issue.
Pluxml is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
Pluxml 0.3.1 is vulnerable to this issue.
Exploit / POC
PluXML Images.PHP Remote Code Execution Vulnerability
Attackers may exploit this issue through a browser.
The following exploit routine is available:
Attackers may exploit this issue through a browser.
The following exploit routine is available:
Solution / Fix
PluXML Images.PHP Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
PluXML Images.PHP Remote Code Execution Vulnerability
References:
References: