PHP Pro Bid 'includes/class_image.php' Remote File Include Vulnerability
BID:34145
Info
PHP Pro Bid 'includes/class_image.php' Remote File Include Vulnerability
| Bugtraq ID: | 34145 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 17 2009 12:00AM |
| Updated: | Mar 17 2009 08:06PM |
| Credit: | Mike Bailey |
| Vulnerable: |
PHP Pro Bid PHP Pro Bid 6.05 |
| Not Vulnerable: | |
Discussion
PHP Pro Bid 'includes/class_image.php' Remote File Include Vulnerability
PHP Pro Bid is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue can allow an attacker to compromise the application and the underlying computer; other attacks are also possible.
PHP Pro Bid 6.05 is vulnerable; other versions may also be affected.
PHP Pro Bid is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue can allow an attacker to compromise the application and the underlying computer; other attacks are also possible.
PHP Pro Bid 6.05 is vulnerable; other versions may also be affected.
Exploit / POC
PHP Pro Bid 'includes/class_image.php' Remote File Include Vulnerability
An attacker can exploit this issue via a browser.
An attacker can exploit this issue via a browser.
Solution / Fix
PHP Pro Bid 'includes/class_image.php' Remote File Include Vulnerability
Solution:
Reports indicate that this issue has been fixed in PHP Pro Bid 6.05; Symantec has not been able to confirm this. Please contact the vendor for more information.
Solution:
Reports indicate that this issue has been fixed in PHP Pro Bid 6.05; Symantec has not been able to confirm this. Please contact the vendor for more information.
References
PHP Pro Bid 'includes/class_image.php' Remote File Include Vulnerability
References:
References:
- PHP Pro Bid Homepage (PHP Pro Bid)