[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] CVE Request: CrawlTrack < 3.2.7 - remote php code execution
From:       Anthon Pang <anthon.pang () gmail ! com>
Date:       2010-12-31 7:16:53
Message-ID: AANLkTikosdxx3yFKdV7t1FA3vqkRgA+Wbhsv1kyBE55J () mail ! gmail ! com
[Download RAW message or body]

Versions of CrawlTrack prior to 3.2.7 are, according to the vendor,
vulnerable to a remote PHP code execution attack if the stats pages
are public

Vendor changelog:  http://www.crawltrack.net/changelog.php

The attack vector isn't disclosed but a diff between 3.2.6 and 3.2.7
show the vendor's fix was to escape special characters (using
http://php.net/htmlspecialchars ) in values supplied through POST
variables.
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic