|
|
MonAlbum "admin_configuration.php" Script Arbitrary PHP Code Injection Vulnerability
|
A vulnerability has been identified in MonAlbum, which could be exploited by remote attackers to execute arbitrary commands. This issue is caused by input validation errors in the "admin/admin_configuration.php" script when writing various parameters to the "conf/config.inc.php" file, which could be exploited by remote attackers to inject malicious code a PHP script and execute arbitrary commands with the privileges of the web server.
MonAlbum version 0.8.7 and prior
VUPEN Security is not aware of any vendor-supplied patch.
http://www.vupen.com/english/advisories/2007/1785
Vulnerability reported by Dj7xpl
2007-05-14 : Initial release
If you have additional information or corrections for this security advisory please submit them via our contact form. | |
|
|
|
Monthly Statistics |
 |
|
|
|
| |
|
Try VUPEN
VNS |
 |
|
 |
|
| |
|
 |
| |
|
|
|
|