WebCalendar config.php PHP远程文件包含漏洞

漏洞信息详情

WebCalendar config.php PHP远程文件包含漏洞

漏洞简介

WebCalendar 1.0.3中的includes/config.php存在PHP远程文件包含漏洞,远程攻击者可通过在includedir参数中的URL(fopen调用中远程访问它,调用的结果是用来定义user_inc设置,该设置用于include_once调用中)来执行任意PHP代码。

漏洞公告

目前厂商已经发布了升级补丁以修复这个安全问题,补丁下载链接:

k5n WebCalendar 1.0

WebCalendar WebCalendar-1.0.4.tar.gz

http://prdownloads.sourceforge.net/webcalendar/WebCalendar-1.0.4.tar.g

z?download

k5n WebCalendar 1.0 RC3

WebCalendar WebCalendar-1.0.4.tar.gz

http://prdownloads.sourceforge.net/webcalendar/WebCalendar-1.0.4.tar.g

z?download

k5n WebCalendar 1.0 RC1

WebCalendar WebCalendar-1.0.4.tar.gz

http://prdownloads.sourceforge.net/webcalendar/WebCalendar-1.0.4.tar.g

z?download

k5n WebCalendar 1.0 rc2

WebCalendar WebCalendar-1.0.4.tar.gz

http://prdownloads.sourceforge.net/webcalendar/WebCalendar-1.0.4.tar.g

z?download

k5n WebCalendar 1.0.1

WebCalendar WebCalendar-1.0.4.tar.gz

http://prdownloads.sourceforge.net/webcalendar/WebCalendar-1.0.4.tar.g

z?download

k5n WebCalendar 1.0.2

WebCalendar WebCalendar-1.0.4.tar.gz

http://prdownloads.sourceforge.net/webcalendar/WebCalendar-1.0.4.tar.g

z?download

k5n WebCalendar 1.0.3

WebCalendar WebCalendar-1.0.4.tar.gz

http://prdownloads.sourceforge.net/webcalendar/WebCalendar-1.0.4.tar.g

z?download

参考网址

来源: VUPEN

名称: ADV-2006-2067

链接:http://www.frsirt.com/english/advisories/2006/2067

来源: SECTRACK

名称: 1016179

链接:http://securitytracker.com/id?1016179

来源: SECUNIA

名称: 20367

链接:http://secunia.com/advisories/20367

来源: BID

名称: 18175

链接:http://www.securityfocus.com/bid/18175

来源: BUGTRAQ

名称: 20060607 Re: WebCalendar-1.0.3 reading of any files

链接:http://www.securityfocus.com/archive/1/archive/1/436263/100/0/threaded

来源: BUGTRAQ

名称: 20060530 WebCalendar-1.0.3 reading of any files

链接:http://www.securityfocus.com/archive/1/435379

来源: OSVDB

名称: 25842

链接:http://www.osvdb.org/25842

来源: DEBIAN

名称: DSA-1096

链接:http://www.debian.org/security/2006/dsa-1096

来源: SREASON

名称: 1019

链接:http://securityreason.com/securityalert/1019

来源: SECUNIA

名称: 20542

链接:http://secunia.com/advisories/20542

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享