|
Family: CGI abuses --> Category: attack
phpBannerExchange Template Class Local File Include Vulnerability Vulnerability Scan
Vulnerability Scan Summary Tries to read a file using phpBannerExchange's template class
Detailed Explanation for this Vulnerability Test
Synopsis :
The remote web server contains a PHP script that is prone to a local
file include flaw.
Description :
The remote host is running phpBannerExchange, a banner exchange script
written in PHP.
The version of phpBannerExchange installed on the remote host uses a
template class that fails to sanitize user-supplied input before using
it in a PHP 'include()' function. An unauthenticated attacker can
exploit this issue to view arbitrary files and possibly to execute
arbitrary PHP code on the affected system subject to the rights of
the web server user id.
See also :
http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042769.html
Solution :
Unknown at this time.
Threat Level:
Low / CVSS Base Score : 2.3
(AV:R/AC:L/Au:NR/C:P/I:N/A:N/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|