漏洞信息详情
PhotoPost 'zipndownload.php'PHP远程文件包含漏洞
漏洞简介
PhotoPost的zipndownload.php中存在PHP远程文件包含漏洞,远程攻击者可以通过PP_PATH参数中的URL执行任意 PHP代码。
漏洞公告
参考网址
来源: BID
名称: 20028
链接:http://www.securityfocus.com/bid/20028
来源: XF
名称: photopost-zipdownload-file-include(28948)
链接:http://xforce.iss.net/xforce/xfdb/28948
来源: BUGTRAQ
名称: 20060914 PhotoPost =>4.6 (PP_PATH) Remote File Inclusion Exploit
链接:http://www.securityfocus.com/archive/1/archive/1/446031/100/0/threaded
来源: SREASON
名称: 1581
链接:http://securityreason.com/securityalert/1581
受影响实体
- Photopost Photopost_php_pro:4.0<!--2000-1-1-->
- Photopost Photopost_php_pro:4.1<!--2000-1-1-->
- Photopost Photopost_php_pro:4.2<!--2000-1-1-->
- Photopost Photopost_php_pro:4.3<!--2000-1-1-->
- Photopost Photopost_php_pro:4.4<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...