Free Arcade Script 'play.php' Local File Include Vulnerability
BID:33869
Info
Free Arcade Script 'play.php' Local File Include Vulnerability
| Bugtraq ID: | 33869 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2009 12:00AM |
| Updated: | Apr 01 2009 05:16PM |
| Credit: | Osirys |
| Vulnerable: |
Free Arcade Script Free Arcade Script 1.0 |
| Not Vulnerable: | |
Discussion
Free Arcade Script 'play.php' Local File Include Vulnerability
Free Arcade Script is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view and execute arbitrary local files in the context of the webserver process. This may aid in further attacks.
Free Arcade Script 1.0 is vulnerable; other versions may also be affected.
Free Arcade Script is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view and execute arbitrary local files in the context of the webserver process. This may aid in further attacks.
Free Arcade Script 1.0 is vulnerable; other versions may also be affected.
Exploit / POC
Free Arcade Script 'play.php' Local File Include Vulnerability
Attackers can exploit this issue via a browser.
The following exploit code is available:
Attackers can exploit this issue via a browser.
The following exploit code is available:
Solution / Fix
Free Arcade Script 'play.php' Local File Include Vulnerability
Solution:
Vendor updates are available. Contact the vendor for more information.
Solution:
Vendor updates are available. Contact the vendor for more information.
References
Free Arcade Script 'play.php' Local File Include Vulnerability
References:
References:
- Vendor Homepage (Free Arcade Script)