Piwik 'unserialize()' PHP Code Execution Vulnerability
BID:37312
Info
Piwik 'unserialize()' PHP Code Execution Vulnerability
| Bugtraq ID: | 37312 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2009 12:00AM |
| Updated: | Dec 17 2009 04:54PM |
| Credit: | Stefan Esser |
| Vulnerable: |
Piwik Piwik 0.2.32 Piwik Piwik 0.4 Piwik Piwik 0.3 |
| Not Vulnerable: |
Piwik Piwik 0.5 |
Discussion
Piwik 'unserialize()' PHP Code Execution Vulnerability
Piwik is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process.
Versions prior to Piwik 0.5 are vulnerable.
Piwik is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process.
Versions prior to Piwik 0.5 are vulnerable.
Exploit / POC
Piwik 'unserialize()' PHP Code Execution Vulnerability
Attackers may exploit this issue through a browser.
Attackers may exploit this issue through a browser.
Solution / Fix
Piwik 'unserialize()' PHP Code Execution Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Piwik 'unserialize()' PHP Code Execution Vulnerability
References:
References:
- Piwik 0.5, response to 'Shocking News in PHP Exploitation' (Piwik)
- Piwik Cookie Unserialize() Vulnerability (SektionEins GmbH)