PhpOursourcing IdeaBox Remote File Include Vulnerability
BID:7488
Info
PhpOursourcing IdeaBox Remote File Include Vulnerability
| Bugtraq ID: | 7488 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 25 2003 12:00AM |
| Updated: | Apr 25 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to euronymous /F0KP. |
| Vulnerable: |
PHPOutsourcing IdeaBox 1.0 |
| Not Vulnerable: | |
Discussion
PhpOursourcing IdeaBox Remote File Include Vulnerability
IdeaBox is prone to a remote file include vulnerability. Remote users may possibly influence the include path for some scripts. As a result, a remote attacker could specify an include path which points to a malicious PHP script with the same name on an external attacker-controlled host.
Exploitation will result in the malicious PHP script being executed with the privileges of the web server hosting the vulnerable software.
IdeaBox is prone to a remote file include vulnerability. Remote users may possibly influence the include path for some scripts. As a result, a remote attacker could specify an include path which points to a malicious PHP script with the same name on an external attacker-controlled host.
Exploitation will result in the malicious PHP script being executed with the privileges of the web server hosting the vulnerable software.
Exploit / POC
PhpOursourcing IdeaBox Remote File Include Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
PhpOursourcing IdeaBox Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.