Alias(es)PHP.PPA.ppa_root_path.Remote.File.Include |
Release DateAug 05, 2005 |
Severitylow |
ImpactCompromise of the affected system. |
DescriptionIt indicates a possible exploit of remote file include vulnerability in PPA software package. A remote php code inclusion vulnerability is reported in it that may allow an attacker to execute arbitrary server side script code on the affected system with privilege of web server process. Due to insufficient sanitization of user input by "functions.inc.php" script, an attacker may modify config[ppa_root_path]" parameter on a HTTP request to reference a URL on a remote web server that contains the malicious code. An attacker may exploit this to execute arbitrary code on the affected system and gain access to it. |
Affected ProductsPPA 0.5.6 |
Recommended ActionsApply appropriate patch from the vendor if available. |
Coverage IPS
VCM |
Reference/shttp://www.securityfocus.com/bid/14209 (BugTraq) |