Family: CGI abuses --> Category: attack
dotProject Remote File Include Vulnerabilities Vulnerability Scan
Vulnerability Scan Summary
Checks for remote file include vulnerabilities in dotProject
Detailed Explanation for this Vulnerability Test
The remote web server contains a PHP application that is affected by
multiple remote file include vulnerabilities.
The remote host is running dotProject, a web-based, open-source,
project management application written in PHP.
The installed version of dotProject fails to sanitize input to various
parameters and scripts before using it to include PHP code. Provided
PHP's 'register_globals' setting is enabled, an unauthenticated
attacker may be able to exploit these flaws to view arbitrary files on
the remote host or to execute arbitrary PHP code, possibly taken from
See also :
Disable PHP's 'register_globals' setting as per the application's
High / CVSS Base Score : 7.0
Click HERE for more information and discussions on this network vulnerability scan.