Description: the master has discovered a vulnerability in MiniBill, which can be exploited by malicious people to compromise a vulnerable system.
Input passed to the "config[include_dir]" parameter in actions/ipn.php isn't properly verified, before it is used to include files. This can be exploited to include arbitrary files from external and local resources.
Successful exploitation requires that "register_globals" is enabled.
The vulnerability has been confirmed in version 1.2.2. Other versions may also be affected.
Solution: The vulnerability has been fixed in version 1.2.3.
Provided and/or discovered by: the master
Changelog: 2006-09-04: Added CVE reference.
2006-10-27: Updated Solution section.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.