JCCorp URLShrink Email Parameter Remote Code Execution Vulnerability

JCcorp URLshrink is prone to a remote code-execution vulnerability because the application fails to sanitize user-supplied input.

An attacker can exploit this issue to execute arbitrary PHP code in the context of the webserver process. This may facilitate a remote compromise of the affected computer; other attacks are also possible.

This issue affects version 1.3.1; other versions may also be affected.


 

Privacy Statement
Copyright 2010, SecurityFocus