Piwik Unspecified PHP Code Execution Vulnerability
BID:48352
Info
Piwik Unspecified PHP Code Execution Vulnerability
| Bugtraq ID: | 48352 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 15 2011 12:00AM |
| Updated: | Jun 15 2011 12:00AM |
| Credit: | Neal Poole |
| Vulnerable: |
Piwik Piwik 1.4 Piwik Piwik 1.3 Piwik Piwik 1.2 |
| Not Vulnerable: |
Piwik Piwik 1.5 |
Discussion
Piwik Unspecified PHP Code Execution Vulnerability
Piwik is prone to an unspecified PHP code-execution vulnerability.
An attacker can exploit this issue to inject and execute arbitrary malicious PHP code in the context of the affected application. This may facilitate a compromise of the application and the underlying system.
Piwik versions 1.2, 1.3, and 1.4 are vulnerable.
Piwik is prone to an unspecified PHP code-execution vulnerability.
An attacker can exploit this issue to inject and execute arbitrary malicious PHP code in the context of the affected application. This may facilitate a compromise of the application and the underlying system.
Piwik versions 1.2, 1.3, and 1.4 are vulnerable.
Exploit / POC
Piwik Unspecified PHP Code Execution Vulnerability
An attacker can use a browser to exploit this issue.
An attacker can use a browser to exploit this issue.
Solution / Fix
Piwik Unspecified PHP Code Execution Vulnerability
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.
References
Piwik Unspecified PHP Code Execution Vulnerability
References:
References: