Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Achievo Remote File Include Command Execution Vulnerability

Achievo includes a PHP script which is used to generate JavaScript (class.atkdateattribute.js.php). This script employs a number of PHP include_once() statements to call code contained in function libraries and grab configuration information. Attackers may subvert the variable ($config_atkroot) which is used to store the location of the external files and specify an arbitrary location, such as an attacker-supplied PHP script on a remote host.

Exploitation of this issue will enable the remote attacker to execute commands with the privileges of the webserver hosting the vulnerable software.







 

Privacy Statement
Copyright 2008, SecurityFocus