This application requires Javascript for optimal performance.

ME.Download.System.Header.Remote.File.Inclusion

Release Date

Nov 16, 2011

Severity

low

Impact

Compromise of affected system.

Description

It indicates a possible exploit of a File Inclusion vulnerability in ME Download System.

This vulnerability may allow a remote attacker to execute arbitrary PHP code, via a URL, in the $Vb8878b936c2bd8ae0cab parameter in the Header.php file.

Affected Products

Ehmig ME Download System 1.3

Recommended Actions

Currently, we are not aware of any vendor-supplied patch for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-4053

Reference/s

http://www.securityfocus.com/bid/19336 (BugTraq)

Reference: VID-29883