Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-1856
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-1856

Description:
plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modifies the configuration file, which allows remote attackers to conduct directory traversal attacks and execute arbitrary local files by placing directory traversal sequences into the maps_type configuration setting, and then sending a request to maps_view.php, which causes plugins/maps/map.main.class.php to use the modified configuration.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41676

SAID
  Secunia Advisory: SA29724

OSVDB
  50229

MILW0RM
  http://www.milw0rm.com/exploits/5392

CONFIRM
  http://sourceforge.net/project/shownotes.php?release_id=595725

BID
  28654


Return to the previous page.