PHPAdsNew contains a flaw that may allow a malicious user to remotely execute arbitrary code. The issue is triggered when an attacker sends a specially crafted HTTP request that sets the includedir variable to include arbitrary files from remote web sites. It is possible that the flaw may allow an attacker to remotely execute arbitrary commands on the system with the same privileges as the webserver resulting in a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Rumored / Private
Disclosure:
OSVDB Verified
OSVDB:
Web Related
Solution
Upgrade to version 2.0 beta 6.1 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the workarounds for versions 2.0 beta 5, 2.0 beta 3, and 1.9.2 as specified by the vendor.