This application requires Javascript for optimal performance.

Idan.Sofer.phphtml.PHP.File.Inclusion

Release Date

Jul 04, 2007

Severity

low

Impact

System compromise.

Description

Idan Sofer PHP::HTML has a remote file include vulnerability. A remote attacker could execute an arbitrary script on a vulnerable web server, with the privileges of the server, via a specially-crafted URL request to the 'phphtml' script, using the 'htmlclass_path' parameter to specify a malicious PHP file from a remote system.

Affected Products

PHP::HTML version 0.6.4 and prior.

Recommended Actions

Currently we are not aware of any official supplied fix for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-3230

Reference/s

http://www.securityfocus.com/bid/24477 (BugTraq)

Reference: VID-14737