PHPOutsourcing Zorum Remote Include Command Execution Vulnerability
BID:6669
Info
PHPOutsourcing Zorum Remote Include Command Execution Vulnerability
| Bugtraq ID: | 6669 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 22 2003 12:00AM |
| Updated: | Jan 22 2003 12:00AM |
| Credit: | Vulnerability discovery credited to MGhz <[email protected]>. |
| Vulnerable: |
PHPOutsourcing Zorum 3.2 PHPOutsourcing Zorum 3.1 PHPOutsourcing Zorum 3.0 |
| Not Vulnerable: |
PHPOutsourcing Zorum 3.3 |
Discussion
PHPOutsourcing Zorum Remote Include Command Execution Vulnerability
It has been reported that Zorum may allow remote users to influence to location of PHP includes. Because of this, it is possible for a remote user to include an external arbitrary PHP script containing commands that may be carried out on the vulnerable host.
It has been reported that Zorum may allow remote users to influence to location of PHP includes. Because of this, it is possible for a remote user to include an external arbitrary PHP script containing commands that may be carried out on the vulnerable host.