OSVDB ID: 22291

Title: ADOdb tmssql.php do Variable Arbitrary PHP Function Execution

Info

Disclosure

Jan 09, 2006

Discovery

Dec 30, 2005

Dates

Exploit

Jan 09, 2006

Solution

Unknown

Description

ADOdb contains a flaw that may allow a malicious user to execute arbitrary PHP functions via the 'do' parameter. The issue is triggered due to the insecure tests/tmssql.php test script. It is possible that the flaw may result in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public, Exploit Unknown
Disclosure: OSVDB Verified, Vendor Verified
OSVDB: Web Related

Solution

Upgrade to version 4.70 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround: remove adodb/tests/tmssql.php file.

Products

John Lim

ADOdb

4.68
4.66

Moodle

Moodle

1.5.3

Mantis

Mantis

0.19.4
1.0.0rc4

Ian Berry

Cacti

0.8.6g

Xaraya Development Group

Xaraya

1.0.1

PostNuke

PostNuke

0.761

PHPOpenChat

PHPOpenChat

3.0.2

Simplog

Simplog

0.9.2

References

Credit

  • Andreas Sandblad - assecunia.com - Secunia Research


Direct URL: http://osvdb.org/22291