vendor:
PAJAX
by:
Matteo Cantoni, hdm
7.5
CVSS
HIGH
Arbitrary PHP code execution and file inclusion
CWE
Product Name: PAJAX
Affected Version From: <=0.5.1
Affected Version To: <=0.5.1
Patch Exists: NO
Related CWE: CVE-2006-1551
CPE:
Platforms Tested:
2006
PAJAX Remote Command Execution
RedTeam has identified two security flaws in PAJAX (<= 0.5.1). It is possible to execute arbitrary PHP code from unchecked user input. Additionally, it is possible to include arbitrary files on the server ending in ".class.php".
Mitigation:
Update to a version higher than 0.5.1