|
|
Info |
Last Modified |
| 4 months ago |
|
|
|
|
Description |
v-creator contains a flaw that may allow a malicious user to execute arbitrary shell commands. The issue is triggered due to an input validation error in the 'enrypt()' and 'decrypt()' functions in VCEngine.php. It is possible that the flaw may allow arbitrary command execution resulting in a loss of integrity.
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Exploit:
Exploit Rumored / Private
Disclosure:
OSVDB Verified
OSVDB:
Web Related
|
|
Technical |
This only affects sites setup with the configuration option VC_CRYPTO_METHOD set to OPENSSL, it does not effect sites with VC_CRYPTO_METHOD set to MCRYPT.
|
|
Solution |
Upgrade to version 1.3-pre3 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.
|
|
Products |
|
v-creator
 |
1.3-pre2 |
|
|
|
|
Credit |
Unknown or Incomplete
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|