myphpPageTool Remote File Include Vulnerability
BID:6744
Info
myphpPageTool Remote File Include Vulnerability
| Bugtraq ID: | 6744 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 03 2003 12:00AM |
| Updated: | Feb 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
Sebastian Bunka myphpPagetool 0.4.3 -1 |
| Not Vulnerable: | |
Discussion
myphpPageTool Remote File Include Vulnerability
myphpPageTool is prone to an issue which may allow remote attackers to include files located on remote servers. This issue is present in several PHP script files in the /doc/admin folder.
Under some circumstances, it is possible for remote attackers to influence the include path for 'pt_config.inc' to point to an external file on a remote server by manipulating some URI parameters.
myphpPageTool is prone to an issue which may allow remote attackers to include files located on remote servers. This issue is present in several PHP script files in the /doc/admin folder.
Under some circumstances, it is possible for remote attackers to influence the include path for 'pt_config.inc' to point to an external file on a remote server by manipulating some URI parameters.