OSVDB ID: 36871

Title: Confixx Pro admin/business_inc/saveserver.php thisdir Parameter Remote File Inclusion

Info

Disclosure

Jul 24, 2007

Discovery

Jul 21, 2007

Dates

Exploit

Jul 24, 2007

Solution

Unknown

Description

Confixx contains a flaw that may allow a remote attacker to execute arbitrary commands. The issue is due to admin/business_inc/saveserver.php not properly sanitizing user input supplied to the 'thisdir' variable. This may allow an attacker to include a file from a remote host that contains arbitrary commands which will be executed by the vulnerable script.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch / RCS
Exploit: Exploit Public, Exploit Unknown
Disclosure: Vendor Verified, Uncoordinated Disclosure
OSVDB: Web Related

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Parallels has released a patch to address this vulnerability.

Products

Parallels

Confixx Pro

2.0.12
3.3.1

References

Credit

  • H4 -


Direct URL: http://osvdb.org/36871