phpBB Auction Module Vulnerable To File Inclusion Exploit phpbb拍卖模块易受列入档案利用
Input passed to the “phpbb_root_path” parameter in “auction/auction_common.php” isn’t properly verified, before it is used to include files.投入,通过向“ phpbb_root_path ”参数,在“拍卖/ auction_common.php ”不是适当核实之前,它是用来包含文件。 This can be exploited to include arbitrary files from external and local resources.这可以被利用来包括任意文件从外部和本地资源。
The vulnerability, discovered by VietMafia, has been confirmed in version 1.3m.的脆弱性,发现vietmafia ,已被证实在版本一点三米。 Other versions may also be affected.其他版本也可能受到影响。
Protection / Solution 保护/解决方案
1. 1 。 Disable “register_globals”禁用“了register_globals ”
2. 2 。 Edit the source code to ensure that input is properly verified.编辑源代码,以确保输入是适当的验证。
via通过 Pridels pridels
Filed under提起下 Computer Security计算机安全 , , Open Source Software开放源码软件 , , PHP PHP的 , , Web网页 , , Web Hosting虚拟主机 , , Web Services Web服务 | |
| |
RSS 2.0 2.0 | |
Trackback Trackback跟踪 this Article |此文章|
Email this Article电子邮件此文章
You may also like to read您也可以想读 |




