This application requires Javascript for optimal performance.

Invisionix.Roaming.System.PageHeaderDefault.File.Inclusion

Release Date

Nov 17, 2011

Severity

low

Impact

Compromise of the affected system.

Description

This indicates a possible exploit of a File Inclusion vulnerability in Invisionix Roaming System that may allow a remote attacker to execute arbitrary PHP code by sending a specially-crafted URL to the pageheaderdefault.inc.php script.

Affected Products

Version 0.2 and prior.

Recommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-4237

Reference/s

http://www.securityfocus.com/bid/19567 (BugTraq)

Reference: VID-29908