Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13758
HistoryAug 07, 2006 - 12:00 a.m.

phpAutoMembersArea 3.2.5 ($installed_config_file) Remote File Inclusion

2006-08-0700:00:00
vulners.com
9

±-------------------------------------------------------------------
+

  • phpAutoMembersArea 3.2.5 ($installed_config_file) Remote File Inclusion

±-------------------------------------------------------------------
+

±-------------------------------------------------------------------
+

  • Code auto_check_renewals.php (line 20):
  • include($installed_config_file);:

±-------------------------------------------------------------------
+

  • $installed_config_file is not properly sanitized before being used

±-------------------------------------------------------------------
+

±-------------------------------------------------------------------
+

±-------------------------------------------------------------------
+

  • Comment:
  • Thanks for the friendly and quick contact with the developer
  • David Walker.
  • Reported the vuln today at 10:04am -> patch available 4:47pm
  • -> ideal!!!

±------------------------[ E O F ]----------------------------------