|
|
docpile:we "INIT_PATH" Parameter Handling Remote PHP File Inclusion Vulnerability
|
A vulnerability has been identified in docpile:we, which could be exploited by attackers to execute arbitrary commands. This flaw is due to input validation errors in various scripts (e.g. "lib/access.inc.php") that fail to validate the "INIT_PATH" parameter, which could be exploited by remote attackers to include malicious files and execute arbitrary commands with the privileges of the web server.
docpile:we version 0.2.2 and prior
Upgrade to version 0.2.3 :
http://docpile-we.berlios.de/download.php
http://www.vupen.com/english/advisories/2006/3222
Vulnerability reported by xoron
2006-08-09 : Initial release
2006-09-19 : Updated Solution
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|