phpScheduleIt Multiple Remote PHP Code Injection Vulnerabilities
BID:33855
Info
phpScheduleIt Multiple Remote PHP Code Injection Vulnerabilities
| Bugtraq ID: | 33855 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-0820 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 20 2009 12:00AM |
| Updated: | Mar 10 2009 10:16PM |
| Credit: | phpScheduleIt |
| Vulnerable: |
phpScheduleIt phpScheduleIt 1.2.10 phpScheduleIt phpScheduleIt 1.2.9 phpScheduleIt phpScheduleIt 1.2.8 phpScheduleIt phpScheduleIt 1.2.7 phpScheduleIt phpScheduleIt 1.2.6 phpScheduleIt phpScheduleIt 1.2.5 phpScheduleIt phpScheduleIt 1.2.4 phpScheduleIt phpScheduleIt 1.2.3 phpScheduleIt phpScheduleIt 1.2.2 |
| Not Vulnerable: |
phpScheduleIt phpScheduleIt 1.2.11 |
Discussion
phpScheduleIt Multiple Remote PHP Code Injection Vulnerabilities
phpScheduleIt is prone to multiple vulnerabilities that attackers can leverage to execute arbitrary PHP code because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
Versions prior to phpScheduleIt 1.2.11 are vulnerable.
phpScheduleIt is prone to multiple vulnerabilities that attackers can leverage to execute arbitrary PHP code because the application fails to adequately sanitize user-supplied input.
Successful attacks can compromise the affected application and possibly the underlying computer.
Versions prior to phpScheduleIt 1.2.11 are vulnerable.
Exploit / POC
phpScheduleIt Multiple Remote PHP Code Injection Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
phpScheduleIt Multiple Remote PHP Code Injection Vulnerabilities
Solution:
The vendor has released an update. Please see the references for more information.
phpScheduleIt phpScheduleIt 1.2.10
phpScheduleIt phpScheduleIt 1.2.5
phpScheduleIt phpScheduleIt 1.2.6
phpScheduleIt phpScheduleIt 1.2.7
phpScheduleIt phpScheduleIt 1.2.8
phpScheduleIt phpScheduleIt 1.2.9
Solution:
The vendor has released an update. Please see the references for more information.
phpScheduleIt phpScheduleIt 1.2.10
-
phpScheduleIt phpScheduleIt_1.2.11.tar.gz
http://downloads.sourceforge.net/phpscheduleit/phpScheduleIt_1.2.11.ta r.gz?use_mirror=jaist
phpScheduleIt phpScheduleIt 1.2.5
-
phpScheduleIt phpScheduleIt_1.2.11.tar.gz
http://downloads.sourceforge.net/phpscheduleit/phpScheduleIt_1.2.11.ta r.gz?use_mirror=jaist
phpScheduleIt phpScheduleIt 1.2.6
-
phpScheduleIt phpScheduleIt_1.2.11.tar.gz
http://downloads.sourceforge.net/phpscheduleit/phpScheduleIt_1.2.11.ta r.gz?use_mirror=jaist
phpScheduleIt phpScheduleIt 1.2.7
-
phpScheduleIt phpScheduleIt_1.2.11.tar.gz
http://downloads.sourceforge.net/phpscheduleit/phpScheduleIt_1.2.11.ta r.gz?use_mirror=jaist
phpScheduleIt phpScheduleIt 1.2.8
-
phpScheduleIt phpScheduleIt_1.2.11.tar.gz
http://downloads.sourceforge.net/phpscheduleit/phpScheduleIt_1.2.11.ta r.gz?use_mirror=jaist
phpScheduleIt phpScheduleIt 1.2.9
-
phpScheduleIt phpScheduleIt_1.2.11.tar.gz
http://downloads.sourceforge.net/phpscheduleit/phpScheduleIt_1.2.11.ta r.gz?use_mirror=jaist
References
phpScheduleIt Multiple Remote PHP Code Injection Vulnerabilities
References:
References:
- phpScheduleIt Changelog 1.2.11 (phpScheduleIt)
- phpScheduleIt Homepage (phpScheduleIt)
- phpScheduleIt Project Page (phpScheduleIt)