[prev in list] [next in list] [prev in thread] [next in thread]
List: oss-security
Subject: [oss-security] CVE Request: CrawlTrack < 3.2.7 - remote php code execution
From: Anthon Pang <anthon.pang () gmail ! com>
Date: 2010-12-31 7:16:53
Message-ID: AANLkTikosdxx3yFKdV7t1FA3vqkRgA+Wbhsv1kyBE55J () mail ! gmail ! com
[Download RAW message or body]
Versions of CrawlTrack prior to 3.2.7 are, according to the vendor,
vulnerable to a remote PHP code execution attack if the stats pages
are public
Vendor changelog: http://www.crawltrack.net/changelog.php
The attack vector isn't disclosed but a diff between 3.2.6 and 3.2.7
show the vendor's fix was to escape special characters (using
http://php.net/htmlspecialchars ) in values supplied through POST
variables.
[prev in list] [next in list] [prev in thread] [next in thread]
Configure |
About |
News |
Add a list |
Sponsored by KoreLogic