phpMyFAQ 'ajax_create_folder.php' Code Injection Vulnerability
BID:50385
Info
phpMyFAQ 'ajax_create_folder.php' Code Injection Vulnerability
| Bugtraq ID: | 50385 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2011 12:00AM |
| Updated: | Oct 26 2011 12:00AM |
| Credit: | EgiX |
| Vulnerable: |
phpMyFAQ phpMyFAQ 2.7 phpMyFAQ phpMyFAQ 2.6.9 phpMyFAQ phpMyFAQ 2.6.8 phpMyFAQ phpMyFAQ 2.6.7 phpMyFAQ phpMyFAQ 2.6.6 phpMyFAQ phpMyFAQ 2.6.5 phpMyFAQ phpMyFAQ 2.6.4 phpMyFAQ phpMyFAQ 2.6.3 phpMyFAQ phpMyFAQ 2.6.2 phpMyFAQ phpMyFAQ 2.6.13 phpMyFAQ phpMyFAQ 2.6.12 phpMyFAQ phpMyFAQ 2.6.11 phpMyFAQ phpMyFAQ 2.6.1 phpMyFAQ phpMyFAQ 2.6.0 |
| Not Vulnerable: |
phpMyFAQ phpMyFAQ 2.7.1 phpMyFAQ phpMyFAQ 2.6.19 |
Discussion
phpMyFAQ 'ajax_create_folder.php' Code Injection Vulnerability
phpMyFAQ is prone to a vulnerability that will let attackers inject and execute arbitrary PHP code.
Remote attackers can exploit this issue to run arbitrary PHP code in the context of the affected application.
phpMyFAQ 2.7.0 is vulnerable; other version may also be affected.
phpMyFAQ is prone to a vulnerability that will let attackers inject and execute arbitrary PHP code.
Remote attackers can exploit this issue to run arbitrary PHP code in the context of the affected application.
phpMyFAQ 2.7.0 is vulnerable; other version may also be affected.
Exploit / POC
phpMyFAQ 'ajax_create_folder.php' Code Injection Vulnerability
Attackers can use a browser to exploit this issue.
Attackers can use a browser to exploit this issue.
Solution / Fix
phpMyFAQ 'ajax_create_folder.php' Code Injection Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
phpMyFAQ 'ajax_create_folder.php' Code Injection Vulnerability
References:
References:
- phpMyFAQ Homepage (phpMyFAQ)
- Remote PHP Code Injection Vulnerability in phpMyFAQ 2.6.18 and 2.7.0 (phpMyFAQ)