Multiple PHP remote file inclusion vulnerabilities in awrate 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the toroot parameter to (1) 404.php or (2) topbar.php, different vectors than CVE-2006-6368.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/26336 | vdb entry |
http://arfis.wordpress.com/2007/09/13/rfi-02-awratecom-message-board/ | |
http://osvdb.org/45528 | vdb entry |
http://osvdb.org/45529 | vdb entry |