Secunia Advisory SA22410OpenDock Full Core "doc_directory" File Inclusion Vulnerabilities
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
Description
Matdhule has reported a vulnerability in OpenDock Full Core, which can be exploited by malicious users to compromise a vulnerable system. Input passed to the "doc_directory" parameter sw/lib_cart/cart.php, sw/lib_cart/lib_cart.php, sw/lib_cart/lib_read_cart.php, and various other files is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources. The vulnerability has been reported in version 4.4. Other versions may also be vulnerable. Solution Provided and/or discovered by Deep Links Do you have additional information related to this advisory?Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this information to vuln@secunia.com
|
||||||||||||||||||||||||||||||||||||||||||||||||||||
204 views | ![]() |
| Limny Multiple Vulnerabilities | |
295 views | ![]() |
| Ubuntu update for thunderbird | |
219 views | ![]() |
| Debian update for php5 | |