Release DateFeb 09, 2007 |
Severityhigh |
ImpactArbitrary PHP code execution. |
DescriptionA PHP remote file inclusion vulnerability in SaveWebPortal 3.4 allows remote attackers to execute arbitrary PHP code via the (1) SITE_Path parameter to menu_dx.php or (2) CONTENTS_Dir parameter to menu_sx.php. |
Affected ProductscirceOS SaveWebPortal 3.4 |
Recommended ActionsCurrently we are not aware of any vendor-supplied patches for this issue. |
Coverage IPS
VCM |
Common Vulnerabilities and Exposures (CVE)CVE-2005-2687 |
Reference/shttp://www.securityfocus.com/bid/19306 (BugTraq) |