Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

DreamAccount Auth.api.PHP Remote File Include Vulnerability

DreamAccount is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary remote PHP commands on an affected computer with the privileges of the webserver process.

Successful exploitation could facilitate unauthorized access; other attacks are also possible.







 

Privacy Statement
Copyright 2009, SecurityFocus