phpRPG Multiple Vulnerabilities
BID:26884
Info
phpRPG Multiple Vulnerabilities
| Bugtraq ID: | 26884 |
| Class: | Unknown |
| CVE: |
CVE-2007-6470 CVE-2007-6469 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | Michael Brooks is credited with the discovery of these issues. |
| Vulnerable: |
phpRPG phpRPG 0.8 |
| Not Vulnerable: | |
Discussion
phpRPG Multiple Vulnerabilities
phpRPG is prone to two vulnerabilities:
- An SQL-injection vulnerability
- A vulnerability that lets remote attackers gain access to sessions.
Exploiting these issues may allow an unauthorized user to steal sessions, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects phpRPG 0.8.0; other versions may also be affected.
phpRPG is prone to two vulnerabilities:
- An SQL-injection vulnerability
- A vulnerability that lets remote attackers gain access to sessions.
Exploiting these issues may allow an unauthorized user to steal sessions, access or modify data, or exploit latent vulnerabilities in the underlying database.
This issue affects phpRPG 0.8.0; other versions may also be affected.
Exploit / POC
phpRPG Multiple Vulnerabilities
Attackers can exploit these issues via a browser.
The following example was provided for the session-stealing vulnerability:
http://www.example.com/phpRPG-0.8.0/tmp/
Attackers can exploit these issues via a browser.
The following example was provided for the session-stealing vulnerability:
http://www.example.com/phpRPG-0.8.0/tmp/
Solution / Fix
phpRPG Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
phpRPG Multiple Vulnerabilities
References:
References: