PHPProfiles Multiple Remote File Include Vulnerabilities

phpProfiles is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.

A successful exploit of these issues allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.

phpProfiles 3.1.2b and prior versions are vulnerable to these issues.


 

Privacy Statement
Copyright 2010, SecurityFocus