Description: Rodrigo Duarte has reported a vulnerability in WORK system e-commerce, which can be exploited by malicious people to compromise a vulnerable system.
Input passed to the "g_include" parameter in include/include_top.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources.
NOTE: Other files are reportedly vulnerable as well.
Successful exploitation requires that "register_globals" is enabled.
The vulnerability is reported in version 3.0.5. Other versions may also be affected.
Solution: Update to version 3.0.863.
Provided and/or discovered by: Rodrigo Duarte
Changelog: 2007-03-14: Added CVE reference.
2007-06-27: Updated "Solution" section.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.