This application requires Javascript for optimal performance.

PHP.MyGuestbook.Form.inc.php3.Remote.File.Include

Release Date

Aug 05, 2005

Severity

low

Impact

Compromise of the affected system.

Description

It indicates a possible exploit of remote file include vulnerability in MyGuestbook software package.



MyGuestbook is a freely available CGI guestbook script, which allows users to leave their name, e-mail and comments. A remote php code inclusion vulnerability is reported in it that may allow an attacker to execute arbitrary server side script code on the affected system with privilege of web server process. Due to insufficient sanitization of user input by form.inc.php3 script, an attacker may modify lang parameter on a HTTP request to reference a URL on a remote web server that contains the malicious code. An attacker may exploit this to execute arbitrary code on the affected system and gain access to it.


Affected Products

MyGuestBook 0.6.1

Recommended Actions

Apply appropriate patch from the vendor if available.

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2005-2162

Reference/s

http://nvd.nist.gov/nvd.cfm?cvename=CAN-2005-2162
http://www.securityfocus.com/bid/14155 (BugTraq)

Reference: VID-10397