java
Multiple vulnerabilities reported in Really Simple PHP and Ajax
Filed in archive AJAX by gautam on April 5, 2007
Multiple vulnerabilities reported in Really Simple PHP and Ajax
Hamid Ebadi has identified multiple vulnerabilities in the case of Really Simple PHP and Ajax or RSPA which hackers could exploit for executing arbitrary commands. This is a high risk vulnerability which can be remotely exploited.

The first security issue is due to input validation errors in framework/Controller_v5.php and framework/Controller_v4.php scripts while processing of _IncludeFilePHPClass and _ClassPath parameters which remote attackers could exploit for inclusion of malicious scripts and execution of arbitrary commands. The second one is caused due to input validation errors in the framework/Controller_v5.php and framework/Controller_v4.php scripts while processing of the __class parameter which remote hackers could exploit for including or disclosing the local file contents with the privileges of the web server.

RSPA 2007-03-23 and earlier versions have been affected by the vulnerability. No details are available as of now regarding any official patch for plugging the hole.


Permalink: Multiple vulnerabilities reported in Really Simple PHP and Ajax
Tags: RSPA  Really  Simple  PHP  and  Ajax  security  vulnerability  ajax  really+simple 
Trackback: http://publish.creative-weblogging.com/publish/mt-tb.pl/61744
img Addthis img Ask img Blinklist img del.icio.us img Digg img Fark img Facebook img Google img Lycos img Ma.gnolia Add this page to Mister Wong Mr Wong img Netscape img Netvousz img Newsvine img Reddit img StumbleUpon img Slashdot img Tailrank img Technorati img Wink img Yahoo

Vote for Multiple vulnerabilities reported in Really Simple PHP and Ajax:

  • Currently 8.67/10
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
Rating: 8.67 out of 3 vote(s) cast.
 
Subscribe
Share It
RSSrss
See all blog subscribe options
Google google
What is RSS?
Yahoo! yahoo
Addthis Subscribe using any feed reader!
Bloglines Bloglines
Newsletter

TwitterFollow us on Twitter!