DynPage 'dynpage_load.php' Local File Disclosure Vulnerability
BID:43018
Info
DynPage 'dynpage_load.php' Local File Disclosure Vulnerability
| Bugtraq ID: | 43018 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2010 12:00AM |
| Updated: | Sep 07 2010 12:00AM |
| Credit: | Abysssec |
| Vulnerable: |
DynPage DynPage 1.0 |
| Not Vulnerable: | |
Discussion
DynPage 'dynpage_load.php' Local File Disclosure Vulnerability
DynPage is prone to a local file-disclosure vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this vulnerability to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
DynPage 1.0 is vulnerable; other versions may also be affected.
DynPage is prone to a local file-disclosure vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit this vulnerability to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
DynPage 1.0 is vulnerable; other versions may also be affected.
Solution / Fix
DynPage 'dynpage_load.php' Local File Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
DynPage 'dynpage_load.php' Local File Disclosure Vulnerability
References:
References:
- Vendor Homepage (Dynpage)