phpMyNewsLetter Remote File Include Vulnerability
BID:5886
Info
phpMyNewsLetter Remote File Include Vulnerability
| Bugtraq ID: | 5886 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2002 12:00AM |
| Updated: | Oct 03 2002 12:00AM |
| Credit: | Discovery credited to Frog Man. |
| Vulnerable: |
phpMyNewsLetter phpMyNewsLetter 0.6.10 |
| Not Vulnerable: | |
Discussion
phpMyNewsLetter Remote File Include Vulnerability
A vulnerability has been discovered in phpMyNewsLetter.
Reportedly, it is possible to pass an attacker-specified file include location to a CGI paramter of the 'customize.php' script.
This may allow an attacker to execute arbitrary commands with the privileges of the webserver.
Additionally, an attacker may exploit this problem to view local webserver readable files.
A vulnerability has been discovered in phpMyNewsLetter.
Reportedly, it is possible to pass an attacker-specified file include location to a CGI paramter of the 'customize.php' script.
This may allow an attacker to execute arbitrary commands with the privileges of the webserver.
Additionally, an attacker may exploit this problem to view local webserver readable files.
Solution / Fix
phpMyNewsLetter Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
phpMyNewsLetter Remote File Include Vulnerability
References:
References:
- PHPMyNewsLetter 0.6.11 - customize.php include problem (Ueli Kistler
)