Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:PHP:PHPWEB-REMOTE-FILE

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

phpWebsite PHP Remote File Include

Release Date

2003/04/22

Update Number

1213

Supported Platforms

di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: phpWebsite PHP Remote File Include


This signature detects attempts to exploit a known vulnerability against phpWebsite. Version 0.8.2 and earlier are vulnerable. Attackers can specify a remote file location for file inclusion to cause phpWebsite to execute arbitrary PHP code; attackers can execute commands with HTTP daemon user permissions.

Extended Description

A vulnerability has been discovered in phpWebsite which allows an attacker to remotely include a malicious PHP file. It is possible for an attacker to specify a remote location for phpWebsite to download an attacker-supplied htmlheader.php script. This issue could be exploited to execute arbitrary commands within the context of the webserver process.

Affected Products

  • phpWebsite 0.8.2

References

  • BugTraq: 5779
  • CVE: CVE-2002-1135
  • URL: http://secunia.com/advisories/7145?menu=lang

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out