|
Achievo Remote File Include Command Execution Vulnerability
Achievo includes a PHP script which is used to generate JavaScript (class.atkdateattribute.js.php). This script employs a number of PHP include_once() statements to call code contained in function libraries and grab configuration information. Attackers may subvert the variable ($config_atkroot) which is used to store the location of the external files and specify an arbitrary location, such as an attacker-supplied PHP script on a remote host. Exploitation of this issue will enable the remote attacker to execute commands with the privileges of the webserver hosting the vulnerable software. |
|
|
Privacy Statement |