| |||||||||||||
| Test Kennung: | 1.3.6.1.4.1.25623.1.0.803116 |
| Kategorie: | Web application abuses |
| Titel: | PRADO PHP Framework 'sr' Parameter Multiple Directory Traversal Vulnerabilities |
| Zusammenfassung: | Check for directory traversal vulnerability in PRADO PHP Framework |
| Beschreibung: | Overview: This host is running PRADO PHP Framework and is prone to multiple directory traversal vulnerabilities. Vulnerability Insight: Input passed to the 'sr' parameter in 'functional_tests.php' and 'functional.php'is not properly sanitised before being used to get the contents of a resource. Impact: Successful exploitation will allow attackers to perform directory traversal attacks and read arbitrary files on the affected application. Impact Level: Application Affected Software/OS: PRADO PHP Framework version 3.2.0 (r3169) Fix: No solution or patch is available as of 20th November, 2012. Information regarding this issue will be updated once the solution details are available. For updates refer to http://www.pradosoft.com References: http://www.exploit-db.com/exploits/22937/ http://cxsecurity.com/issue/WLB-2012110184 http://packetstormsecurity.org/files/118348/ZSL-2012-5113.txt http://www.zeroscience.mk/en/vulnerabilities/ZSL-2012-5113.php |
| Querverweis: |
BugTraq ID: 56677 |
| Copyright | Copyright (c) 2012 Greenbone Networks GmbH |
| Dies ist nur einer von 32582 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus. Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten. |
|