This application requires Javascript for optimal performance.

WoW.Roster.subdir.Parameter.Handling.File.Inclusion

Release Date

Nov 03, 2011

Severity

high

Impact

System Compromise: Arbitrary PHP code execution.

Description

This indicates an attempt to exploit a PHP remote File Inclusion vulnerability in WoWRoster (aka World of Warcraft Roster).

The vulnerability in "conf.php" may allow remote attackers to execute arbitrary PHP code via a URL in the "subdir" parameter.

Affected Products

WoW Roster WoW Roster 1.5.1
WoW Roster WoW Roster 1.5

Recommended Actions

Currently we are not aware of any official vendor supplied patch for this issue.
WoWRoster Web site: http://www.wowroster.net/

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2006-3998

Reference/s

http://www.frsirt.com/english/advisories/2006/3094 (FrSIRT)

Reference: VID-29619