|
|
FOAFgen "foaf" Parameter Handling Remote Directory Traversal Vulnerability
|
A vulnerability has been identified in FOAFgen, which could be exploited by attackers to gain unauthorized access to arbitrary files on a vulnerable system. This flaw is due to an input validation error in the "redir.php" script that does not validate the "foaf" parameter before being passed to a "readfile()" call, which could be exploited by malicious users to access and read the contents of arbitrary files.
FOAFgen version 0.3 and prior
VUPEN Security is not aware of any vendor-supplied patch.
http://www.vupen.com/english/advisories/2006/4009
Vulnerability reported by DarkFig
2006-10-11 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|