Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0390 (AuraCMS, Mod Block Statistik)

BugsAlert Home > CVE-2008-0390 (AuraCMS, Mod Block Statistik)
 
 

stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into online.db.txt via the X-Forwarded-For HTTP header in a stat action to index.php, and execute online.db.txt via a certain request to index.php.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0390

Learn more about CVE-2008-0390 (AuraCMS, Mod Block Statistik)
 
Tags: cve-2008-0390 auracms mod block statistik

Related Items

      Debian update for xwine

      #967: nightly page for browser compatibility test gives 404

      CVE-2008-4535 (ec-cube)

      CVE-2008-0407 (HTTP File Server)

      FrSIRT - Slackware Security Update Fixes Xine-lib Code Execution Vulnerability

      contradictions in isset docs

      Fake RootkitBuster Busted!

 

Pixel