Cafelog b2 Remote File Include Vulnerability
BID:7738
Info
Cafelog b2 Remote File Include Vulnerability
| Bugtraq ID: | 7738 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 29 2003 12:00AM |
| Updated: | May 29 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to pokleyzz <[email protected]>. |
| Vulnerable: |
Cafelog b2 0.6.1 Cafelog b2 0.6 pre2 Cafelog b2 0.6 pre |
| Not Vulnerable: | |
Discussion
Cafelog b2 Remote File Include Vulnerability
A remote file include vulnerability has been reported for Cafelog. Due to insufficient sanitization of some user-supplied variables by the 'blogger-2-b2.php' and 'gm-2-b2.php' scripts, it is possible for a remote attacker to include a malicious PHP file in a URL.
If the remote file is a malicious PHP script, this may allow for execution of attacker-supplied PHP code with the privileges of the web server.
A remote file include vulnerability has been reported for Cafelog. Due to insufficient sanitization of some user-supplied variables by the 'blogger-2-b2.php' and 'gm-2-b2.php' scripts, it is possible for a remote attacker to include a malicious PHP file in a URL.
If the remote file is a malicious PHP script, this may allow for execution of attacker-supplied PHP code with the privileges of the web server.