Family: CGI abuses --> Category: attack
Jinzora include_path Parameter Remote File Include Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary
Tries to read a local file with Jinzora
Detailed Explanation for this Vulnerability Test
The remote web server contains a PHP application that is affected by
multiple remote file include issues.
The remote host is running Jinzora, a web-based media streaming and
management system written in PHP.
The installation of Jinzora on the remote host fails to sanitize input
to the 'include_path' parameter of several scripts before using it in
the 'jzBackend.php' script to include PHP code. Provided PHP's
'register_globals' setting is enabled, an unauthenticated attacker may
be able to exploit these issues to view arbitrary files or to execute
arbitrary PHP code on the remote host, subject to the rights of
the web server user id.
See also :
Unknown at this time.
Medium / CVSS Base Score : 5.6
Click HERE for more information and discussions on this network vulnerability scan.