|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> CGI abuses >> Jinzora include_path Parameter Remote File Include Vulnerabilities Vulnerability Assessment Details
|
Jinzora include_path Parameter Remote File Include Vulnerabilities |
||
Tries to read a local file with Jinzora Detailed Explanation for this Vulnerability Assessment Summary : The remote web server contains a PHP application that is affected by multiple remote file include issues. Description : The remote host is running Jinzora, a web-based media streaming and management system written in PHP. The installation of Jinzora on the remote host fails to sanitize input to the 'include_path' parameter of several scripts before using it in the 'jzBackend.php' script to include PHP code. Provided PHP's 'register_globals' setting is enabled, an unauthenticated attacker may be able to exploit these issues to view arbitrary files or to execute arbitrary PHP code on the remote host, subject to the rights of the web server user id. See also : http://milw0rm.com/exploits/3003 Solution : Unknown at this time. Network Security Threat Level: Medium / CVSS Base Score : 5.6 (AV:R/AC:H/Au:NR/C:P/I:P/A:P/B:N) Networks Security ID: 21741 Vulnerability Assessment Copyright: This script is Copyright (C) 2007 Tenable Network Security |
||
Cables, Connectors |
AMD EPYC 7282 CPU Processor 16 Cores 32 Threads 2.8GHZ up to 3.2GHZ 120W no lock
$75.00
AMD Ryzen 9 5950X 16-core 32-thread Desktop Processor
$319.99
Intel - Core i7-12700K Desktop Processor 12 (8P+4E) Cores up to 5.0 GHz Unloc...
$419.99
Intel - Core i9-12900K Desktop Processor 16 (8P+8E) Cores up to 5.2 GHz Unloc...
$619.99
Intel Xeon E5-2697A V4 2.6GHz CPU Processor 16-Core Socket LGA2011 SR2K1
$39.99
Intel Xeon E5-2680 v4 SR1N7 2.4GHz 14-Core 3.5MB 35MB Socket 2011-3 Server CPU
$11.99
Intel Core i5-8500 SR3XE 3.0GHz 6 Core LGA1151 9MB Processor CPU Tested
$47.00
AMD Ryzen 5 4500 6-Core 3.6GHz Socket AM4 65W CPU Desktop Processor
$79.00
Intel Core i7-3770 3.40GHz 8MB Quad Core Socket LGA1155 CPU Processor SR0PK
$35.00
Intel 16 Core i7-13700T DESKTOP processor TURBO Boost 4.90Ghz CM8071504820903
$269.00
|
||
No Discussions have been posted on this vulnerability. |