|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> CGI abuses >> Siteframe LOCAL_PATH Remote File Include Vulnerability Vulnerability Assessment Details
|
Siteframe LOCAL_PATH Remote File Include Vulnerability |
||
Checks for LOCAL_PATH remote file include vulnerability in Siteframe Detailed Explanation for this Vulnerability Assessment Summary : The remote web server contains a PHP script that is prone to a remote file include attack. Description : The remote host is running Siteframe, an open-source content management system using PHP and MySQL. The installed version of Siteframe does not properly sanitize the 'LOCAL_PATH' parameter of the 'siteframe.php' script before using it to include files. By leveraging this flaw, a possible hacker is able to view arbitrary files on the remote host and even execute arbitrary PHP code, possibly taken from third-party hosts. See also : http://securitytracker.com/alerts/2005/Jun/1014150.html http://v3.siteframe.org/document.php?id=483 Solution : Patch 'siteframe.php' as suggested in the project document referenced above. Network Security Threat Level: High / CVSS Base Score : 7 (AV:R/AC:L/Au:NR/C:P/A:P/I:P/B:N) Networks Security ID: 13928 Vulnerability Assessment Copyright: This script is Copyright (C) 2005-2006 Tenable Network Security |
||
Cables, Connectors |
Vintage Apple Macintosh Computer Modem A9M0300
$65.00
Vintage 1999 MacAcademy 2 CD-ROMs Quick Start iMac & Mac OS 8.5 Speed Learning
$3.00
Casio HW-JS Vintage Word Processor w/ Printer
$75.00
Lot Of 2 "As Is" Vintage Miniscribe 3180E 5.25" HH ESDI Drives
$95.00
Vintage Atari 1200XL Computer with video upgrade, works great.
$400.00
Radio Shack Vintage Pc Circuit Boards
$40.00
Vintage Compaq 141649-004 2 Button PS/2 Gray Mouse M-S34 - FAST SHIPPING - NEW
$8.99
RARE NEW RETAIL BOX VINTAGE AST BTC 5140M WINDOWS PS2 KEYBOARD FCC E5XK8M104M10U
$29.95
Vintage Toshiba SatellitePro 435CDS Retro Laptop • Pentium 16MB CD-ROM POSTS
$89.00
Vintage IBM Aptiva E-5u Desktop Computer. IBM’s First Sub-$1000 Computer.
$140.00
|
||
No Discussions have been posted on this vulnerability. |