This application requires Javascript for optimal performance.

Php.Blue.Dragon.Activecontent.PHP.File.Inclusion

Release Date

Sep 07, 2007

Severity

low

Impact

System compromise, remote script execution.

Description

Php Blue Dragon CMS has a remote file inclusion vulnerability. A remote attacker could execute arbitrary scripts on a web server with the privileges of the server via a specially crafted URL request to the 'public_includes/pub_blocks/activecontent.php' script, by using the 'vsDragonRootPath' parameter to specify a malicious PHP file from a remote system.

Affected Products

Php Blue Dragon CMS version 3.0.0 and prior.

Recommended Actions

Currently we are not aware of any official fix for this issue.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2007-4313

Reference/s

http://www.securityfocus.com/bid/25264 (BugTraq)

Reference: VID-14953