OSVDB ID: 30230

Title: Advanced Guestbook admin.php include_path Parameter Remote File Inclusion

Info

Disclosure

Nov 03, 2006

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Unknown

Description

Advanced Guestbook has been reported to contain a flaw that may allow a remote attacker to execute arbitrary commands. The issue is supposedly due to the admin.php script not properly sanitizing user input supplied to the 'include_path' variable. However, subsequent examination indicates that the variable is previously set and can not be manipulated by an attacker.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
OSVDB: Web Related, Myth / Fake

Solution

The vulnerability reported is incorrect. No solution required.

Products

Chi Kien Uong

Advanced Guestbook

2.3.1

References

Credit

  • BrokeN-ProXy - broken-proxylinuxmail.org -


Direct URL: http://osvdb.org/30230