PHP remote file inclusion vulnerability in BlackBoard 1.5.1 allows remote attackers to execute arbitrary PHP code by modifying the libpath parameter (incorrectly called "libpach") to reference a URL on a remote web server that contains _more.php, as demonstrated using checkdb.inc.php.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/17637 | vdb entry |
http://blackboard.unclassified.de/70%2C1#1031 | |
http://www.securityfocus.com/bid/11336 | patch vdb entry |
http://marc.info/?l=bugtraq&m=109707701719659&w=2 | mailing list |
http://secunia.com/advisories/12757 | patch vendor advisory third party advisory |