|
|
WEBalbum "skin2" Cookie Parameter Handling Local File Inclusion Vulnerability
|
A vulnerability has been identified in WEBalbum, which could be exploited by remote attackers to bypass security restrictions, gain knowledge of sensitive information, and compromise a vulnerable server. This flaw is due to an input validation when processing the "skin2" cookie parameter, which could be exploited by remote attackers to inject and execute arbitrary commands with the privileges of the web server by including local files (e.g. log files).
WEBalbum version 2.02 and prior
VUPEN Security is not aware of any vendor-supplied patch.
http://www.vupen.com/english/advisories/2006/1108
Vulnerabilities reported by rgod
2006-03-27 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|