Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Thorsten Korner 123tkShop Arbitrary File Include Vulnerability

Solution:
Configure PHP such that the 'register_globals' option is set to 'off'. Allowing CGI parameters to automatically enter global variable space is a well known security risk. This option may, however, impact scripts which rely on this feature.

Usage of the PHP option 'magic_quotes_gpc' may reduce the consequences of exploitation by not allowing the attacker to use the null (0x00) character to terminate include strings.

The vendor has released a new version that addresses this vulnerability:


Thorsten Korner 123tkShop 0.2

Thorsten Korner 123tkShop 0.3







 

Privacy Statement
Copyright 2009, SecurityFocus