Family: CGI abuses --> Category: attack
phpPgAdmin formLanguage Parameter Local File Include Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Checks for formLanguage parameter directory traversal vulnerability in phpPgAdmin
Detailed Explanation for this Vulnerability Test
The remote web server contains a PHP script that is affected by a
local file include vulnerability.
The remote host is running phpPgAdmin, a web-based administration tool
The installed version of phpPgAdmin fails to filter directory
traversal sequences from user-input supplied to the 'formLanguage'
parameter of the login form. A possible hacker can exploit this issue to
read files outside the application's document directory and to include
arbitrary PHP files from the remote host, subject to the rights of
the web server userid.
See also :
Upgrade to phpPgAdmin 3.5.4 or later.
Medium / CVSS Base Score : 6
Click HERE for more information and discussions on this network vulnerability scan.