DotProject Remote File Include Vulnerability
BID:6710
Info
DotProject Remote File Include Vulnerability
| Bugtraq ID: | 6710 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 28 2003 12:00AM |
| Updated: | Jan 28 2003 12:00AM |
| Credit: | Discovery of this issue is credited to [email protected]. |
| Vulnerable: |
dotmarketing.org dotproject dev20030121 |
| Not Vulnerable: | |
Discussion
DotProject Remote File Include Vulnerability
dotproject is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers. Under some circumstances, it is possible for a remote attacker to influence the include path of a script to point to an external file on a remote server.
If the remote file is a malicious PHP script, This may be exploited to execute arbitrary commands in the context of the webserver.
dotproject is prone to an issue which may allow remote attackers to include arbitrary files located on remote servers. Under some circumstances, it is possible for a remote attacker to influence the include path of a script to point to an external file on a remote server.
If the remote file is a malicious PHP script, This may be exploited to execute arbitrary commands in the context of the webserver.
Exploit / POC
DotProject Remote File Include Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
DotProject Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
DotProject Remote File Include Vulnerability
References:
References:
- dotproject Homepage (dotmarketing.org)
- dotproject Remote Code Execution Vulnerability ([email protected])
- Re: dotproject Remote Code Execution Vulnerability : Patch ("Frog Man"
)