vendor:
GeekLog
by:
Kw3[R]Ln [Romanian Security Team]
N/A
CVSS
N/A
Remote File Include
Unknown
CWE
Product Name: GeekLog
Affected Version From: 1.4.2000
Affected Version To: 1.4.2000
Patch Exists: NO
Related CWE: Unknown
CPE: Unknown
Platforms Tested: Unknown
Unknown
GeekLog <= 1.4.0 (_CONF[path]) Remote File Include Vulnerabilities
Variable $_CONF[path] not sanitized. When register_globals=on an attacker can exploit this vulnerability with a simple PHP injection script. The vulnerability can be exploited by injecting an evil script into the _CONF[path] parameter in various plugins of GeekLog. The affected plugins include links, polls, spamx, and more.
Mitigation:
Unknown