PHP-Barcode 'code' Parameter Remote Command Injection Vulnerability
BID:48885
Info
PHP-Barcode 'code' Parameter Remote Command Injection Vulnerability
| Bugtraq ID: | 48885 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2011 12:00AM |
| Updated: | Jul 26 2011 12:00AM |
| Credit: | beford |
| Vulnerable: |
PHP-Barcode PHP-Barcode 0.3pl1 |
| Not Vulnerable: | |
Discussion
PHP-Barcode 'code' Parameter Remote Command Injection Vulnerability
PHP-Barcode is prone to a remote command-injection vulnerability.
Attackers can exploit this issue to execute arbitrary commands in the context of the application.
PHP-Barcode 0.3pl1 is affected; other versions may also be vulnerable.
PHP-Barcode is prone to a remote command-injection vulnerability.
Attackers can exploit this issue to execute arbitrary commands in the context of the application.
PHP-Barcode 0.3pl1 is affected; other versions may also be vulnerable.
Exploit / POC
PHP-Barcode 'code' Parameter Remote Command Injection Vulnerability
The following URI is available:
http://www.example.com/php-barcode/barcode.php?code=%cmd%
The following URI is available:
http://www.example.com/php-barcode/barcode.php?code=%cmd%
Solution / Fix
PHP-Barcode 'code' Parameter Remote Command Injection Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
References
PHP-Barcode 'code' Parameter Remote Command Injection Vulnerability
References:
References:
- Homepage (Folke Ashberg)