OSVDB ID: 1963

Title: phpAdsNew helperfunction.php Remote File Inclusion

Info

Disclosure

Oct 02, 2001

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

PHPAdsNew contains a flaw that may allow a malicious user to remotely execute arbitrary code. The issue is triggered when an attacker sends a specially crafted HTTP request that sets the includedir variable to include arbitrary files from remote web sites. It is possible that the flaw may allow an attacker to remotely execute arbitrary commands on the system with the same privileges as the webserver resulting in a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Rumored / Private
Disclosure: OSVDB Verified
OSVDB: Web Related

Solution

Upgrade to version 2.0 beta 6.1 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the workarounds for versions 2.0 beta 5, 2.0 beta 3, and 1.9.2 as specified by the vendor.

Products

PHPAdsNew

PHPAdsNew

0.x
1.x
2.0 Beta 1
2.0 Beta 2
2.0 Beta 3
2.0 Beta 4
2.0 Beta 5
2.0 Beta 6
2.0 Beta 6.1

References

Credit

  • atil - bugtraqBrand New Doo Doojakob.weite-welt.com -
  • genetics - veenstraBrand New Doo Doochello.nl -


Direct URL: http://osvdb.org/36218