OSVDB ID: 6530

Title: e107 secure_img_render.php p Parameter Remote File Inclusion

Info

Disclosure

May 29, 2004

Discovery

May 29, 2004

Dates

Exploit

May 29, 2004

Solution

Unknown

Description

e107 contains a flaw that may allow arbitrary command execution. The issue is triggered when the "p" parameter in the script "secure_img_render.php" is not properly verified. It is possible that the flaw may allow a malicious user to include arbitrary scripts and files from local or remote resources which will be executed on the vulnerable server, resulting in a loss of integrity.

Classification

Location: Remote / Network Access
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Public
OSVDB: Web Related

Solution

Upgrade to version 0.616 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known worka

Products

e107 Inc.

e107

0.614
0.615

References

Credit

  • Janek Vind "waraxe" - come2waraxeyahoo.com - Personal Page


Direct URL: http://osvdb.org/6530