PHPKIT contains a flaw that allows remote code execution. This flaw exists because the application does not validate variables upon submission to the scripts utilizing its template engine. This could allow a user to execute remote code, leading to a loss of integrity.
Classification
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
OSVDB:
Web Related
Technical
This vulnerability is only present when the register_globals PHP option is set to 'on'. This has not been the default setting for PHP installs since version 4.2.0 (22-Apr-2002).
Solution
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.