PHPGroupWare Unspecified Remote File Include Vulnerability
BID:8265
Info
PHPGroupWare Unspecified Remote File Include Vulnerability
| Bugtraq ID: | 8265 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 23 2003 12:00AM |
| Updated: | Jul 23 2003 12:00AM |
| Credit: | The discoverer of this vulnerability is, at present, unknown. |
| Vulnerable: |
PHPGroupWare PHPGroupWare 0.9.14 .005 PHPGroupWare PHPGroupWare 0.9.14 .003 PHPGroupWare PHPGroupWare 0.9.13 PHPGroupWare PHPGroupWare 0.9.12 |
| Not Vulnerable: |
PHPGroupWare PHPGroupWare 0.9.14 .006 |
Discussion
PHPGroupWare Unspecified Remote File Include Vulnerability
phpGroupWare is prone to a vulnerability that may permit remote attackers, without prior authentication, to include and execute malicious PHP scripts. Remote users may influence URI variables to include a malicious PHP script on a remote system, it is possible to cause arbitrary PHP code to be executed. This would occur in the context of the web server.
phpGroupWare is prone to a vulnerability that may permit remote attackers, without prior authentication, to include and execute malicious PHP scripts. Remote users may influence URI variables to include a malicious PHP script on a remote system, it is possible to cause arbitrary PHP code to be executed. This would occur in the context of the web server.
Exploit / POC
PHPGroupWare Unspecified Remote File Include Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
PHPGroupWare Unspecified Remote File Include Vulnerability
Solution:
Mandrake has released an advisory (MDKSA-2003:077) to address this issue. Information regarding obtaining and applying fixes can be found in the referenced advisory. Affected users are advised to apply the patches as soon as possible.
Conectiva has released an advisory (CLA-2003:703) to address this issue. Information regarding obtaining and applying fixes can be found in the referenced advisory. Affected users are advised to apply the patches as soon as possible.
The vendor has released a fix to address this issue; users are advised to apply the fix as soon as possible:
PHPGroupWare PHPGroupWare 0.9.12
PHPGroupWare PHPGroupWare 0.9.13
PHPGroupWare PHPGroupWare 0.9.14 .003
PHPGroupWare PHPGroupWare 0.9.14 .005
Solution:
Mandrake has released an advisory (MDKSA-2003:077) to address this issue. Information regarding obtaining and applying fixes can be found in the referenced advisory. Affected users are advised to apply the patches as soon as possible.
Conectiva has released an advisory (CLA-2003:703) to address this issue. Information regarding obtaining and applying fixes can be found in the referenced advisory. Affected users are advised to apply the patches as soon as possible.
The vendor has released a fix to address this issue; users are advised to apply the fix as soon as possible:
PHPGroupWare PHPGroupWare 0.9.12
-
phpGroupWare phpGroupWare 0.9.14.006
http://www.phpgroupware.org/downloads/
PHPGroupWare PHPGroupWare 0.9.13
-
phpGroupWare phpGroupWare 0.9.14.006
http://www.phpgroupware.org/downloads/
PHPGroupWare PHPGroupWare 0.9.14 .003
-
phpGroupWare phpGroupWare 0.9.14.006
http://www.phpgroupware.org/downloads/
PHPGroupWare PHPGroupWare 0.9.14 .005
-
phpGroupWare phpGroupWare 0.9.14.006
http://www.phpgroupware.org/downloads/
References
PHPGroupWare Unspecified Remote File Include Vulnerability
References:
References:
- PHPGroupWare Homepage (PHPGroupWare)