|
|
Info |
Last Modified |
| 5 months ago |
|
|
|
|
Description |
NOCC contains a flaw that may allow a malicious user to execute arbitrary code on the target server. The issue is triggered because the application fails to properly sanitize input supplied to the 'functions.php' script via the 'Accept-Language' HTTP header filed. It is possible that the flaw may allow an attacker to include an arbitrary .php file from the server, which will be executed under the privilege of the web server.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Available
OSVDB:
Web Related
|
|
Solution |
Currently, there are no known upgrades, patches, or workarounds available to correct this issue.
|
|
Products |
|
NOCC
 |
1.0 |
|
|
|
|
|
|
Credit |
- retrogod - rgod
austici.org - Personal Page
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|