PTK 'file_content.php' Arbitrary Command Execution and Unspecified Input Validation Vulnerabilities
BID:32128
Info
PTK 'file_content.php' Arbitrary Command Execution and Unspecified Input Validation Vulnerabilities
| Bugtraq ID: | 32128 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6793 |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 05 2008 12:00AM |
| Updated: | May 07 2015 05:21PM |
| Credit: | Luca "ikki" Carettoni |
| Vulnerable: |
DFLabs PTK 1.0 DFLabs PTK 0.2 DFLabs PTK 0.1 |
| Not Vulnerable: |
DFLabs PTK 1.0.1 |
Discussion
PTK 'file_content.php' Arbitrary Command Execution and Unspecified Input Validation Vulnerabilities
PTK is prone to a vulnerability that lets attackers execute arbitrary commands because it fails to properly sanitize user-supplied input. In addition, the application is prone to multiple unspecified input-validation vulnerabilities.
An attacker may exploit these issues to execute arbitrary commands in the context of the vulnerable application. Other attacks may also be possible.
Versions prior to PTK 1.0.1 are vulnerable.
PTK is prone to a vulnerability that lets attackers execute arbitrary commands because it fails to properly sanitize user-supplied input. In addition, the application is prone to multiple unspecified input-validation vulnerabilities.
An attacker may exploit these issues to execute arbitrary commands in the context of the vulnerable application. Other attacks may also be possible.
Versions prior to PTK 1.0.1 are vulnerable.
Exploit / POC
PTK 'file_content.php' Arbitrary Command Execution and Unspecified Input Validation Vulnerabilities
An attacker requires local interactive access to a vulnerable computer.
An attacker requires local interactive access to a vulnerable computer.
Solution / Fix
PTK 'file_content.php' Arbitrary Command Execution and Unspecified Input Validation Vulnerabilities
Solution:
The vendor has released PTK 1.0.1 to address these issues.
Solution:
The vendor has released PTK 1.0.1 to address these issues.
References
PTK 'file_content.php' Arbitrary Command Execution and Unspecified Input Validation Vulnerabilities
References:
References: