|
|
Info |
Last Modified |
| 10 months ago |
|
|
|
|
Description |
CoolPHP contains a flaw that allows a remote attacker to include arbitrary files on the remote system, allowing for remote command execution. The issue is due to the index.php script not properly sanitizing user input, specifically traversal style attacks (../../) supplied via the 'op' variable. This may allow an attacker to specify an arbitrary file on the system to be read and processed by CoolPHP.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Exploit:
Exploit Available
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
CoolPHP
 |
1.0-stable |
|
|
|
|
|
|
|
Credit |
- R00tCr4ck - root
cyberspy.org -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|