Editor Login | Register
Ekle

> World > Security
Ksemail language Local File Inclusion Vulnerability - Security - World -
CWRedLight
(Date : 11.04.2008 17:19:02)


Ksemail language Local File Inclusion Vulnerability
Secunia Advisory: SA29776  
Release Date: 2008-04-11

Critical:
Moderately critical
Impact: Exposure of system information
Exposure of sensitive information
Where: From remote
Solution Status: Unpatched

Software:Ksemail 6.x

Description:
dun has reported a vulnerability in Ksemail, which can be exploited by malicious people to disclose sensitive information.

Input passed via the "language" parameter to index.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local resources via directory traversal attacks.

Solution:
Filter malicious characters and character sequences in a web proxy.

Provided and/or discovered by:
dun

Original Advisory:
http://milw0rm.com/exploits/5423











Derecelendir
Kaynak http://secunia.com/advisories/29776/
İçerik İhbarı
Bağlantılar: bilgininefendisi.net

Open Source Document Project AUP&TOS