Kietu Hit.PHP Remote File Inclusion Vulnerability
BID:6863
Info
Kietu Hit.PHP Remote File Inclusion Vulnerability
| Bugtraq ID: | 6863 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 15 2003 12:00AM |
| Updated: | Feb 15 2003 12:00AM |
| Credit: | Discovery of this issue is credited to Frog Man <[email protected]>. |
| Vulnerable: |
Kietu Kietu 3.1 Kietu Kietu 3.0 Kietu Kietu 2.3 Kietu Kietu 2.0 |
| Not Vulnerable: | |
Discussion
Kietu Hit.PHP Remote File Inclusion Vulnerability
Kietu may permit remote attackers to specify the include path for a configuration file. An attacker may exploit this to include a malicious PHP script from a remote host, resulting in execution of arbitrary commands with the privileges of the webserver process.
Kietu may permit remote attackers to specify the include path for a configuration file. An attacker may exploit this to include a malicious PHP script from a remote host, resulting in execution of arbitrary commands with the privileges of the webserver process.
Exploit / POC
Kietu Hit.PHP Remote File Inclusion Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Kietu Hit.PHP Remote File Inclusion Vulnerability
References:
References:
- 5 holes, Part 8 (Frog Man)
- Kietu Homepage (Kietu)