漏洞信息详情
PHPRaid 多个远程文件包含漏洞
- CNNVD编号:CNNVD-200606-600
- 危害等级: 中危
- CVE编号:
CVE-2006-3317
- 漏洞类型:
输入验证
- 发布时间:
2006-06-29
- 威胁类型:
远程
- 更新时间:
2006-07-03
- 厂 商:
spiffyjr - 漏洞来源:
These issues were … -
漏洞简介
phpRaid 3.0.6中的PHP远程文件包含漏洞。远程攻击者通过(1) announcements.php和(2) rss.php的phpraid_dir参数中的URL执行任意代码。
参考网址
来源: BUGTRAQ
名称: 20060629 Secunia Research: phpRaid SQL Injection and File InclusionVulnerabilities
链接:http://www.securityfocus.com/archive/1/archive/1/438706/100/0/threaded
来源: VUPEN
名称: ADV-2006-2593
链接:http://www.frsirt.com/english/advisories/2006/2593
来源: MISC
链接:http://secunia.com/secunia_research/2006-47/advisory/
来源: SECUNIA
名称: 20865
链接:http://secunia.com/advisories/20865
来源: XF
名称: phpraid-rss-file-include(33100)
链接:http://xforce.iss.net/xforce/xfdb/33100
来源: XF
名称: phpraid-announcements-file-include(27462)
链接:http://xforce.iss.net/xforce/xfdb/27462
来源: BID
名称: 23066
链接:http://www.securityfocus.com/bid/23066
来源: BID
名称: 18719
链接:http://www.securityfocus.com/bid/18719
来源: www.phpraider.com
链接:http://www.phpraider.com/index.php?action=tpmod;dl=item10
来源: OSVDB
名称: 26889
来源: OSVDB
名称: 26888
来源: MILW0RM
名称: 3528
链接:http://www.milw0rm.com/exploits/3528
来源: SREASON
名称: 1173
链接:http://securityreason.com/securityalert/1173
来源: FULLDISC
名称: 20060629 Secunia Research: phpRaid SQL Injection and File Inclusion Vulnerabilities
链接:http://archives.neohapsis.com/archives/fulldisclosure/2006-06/0824.html