| VID |
21889 |
| Severity |
30 |
| Port |
80, ... |
| Protocol |
TCP |
| Class |
CGI |
| Detailed Description |
The phpWebFTP is vulnerable to a local file include vulnerability via the 'language' parameter. phpWebFTP is a web-based FTP client written in PHP. phpWebFTP version 3.3a and earlier versions are vulnerable to a local file include vulnerability, caused by improper validation of user-supplied input passed to the 'language' parameter of the 'index.php' script. A remote attacker could exploit this vulnerability to view arbitrary files or to execute arbitrary PHP script code on the vulnerable system in the security context of the Web server process.
* References: http://www.securityfocus.com/archive/1/431115/30/0/threaded http://www.frsirt.com/english/advisories/2006/1388
* Platforms Affected: phpWebFTP version 3.3a and earlier versions Any operating system Any version |
| Recommendation |
Upgrade to the latest version of phpWebFTP (3.3b or later), available from the phpWebFTP Web site at http://www.v-wijk.net/ |
| Related URL |
CVE-2006-1813 (CVE) |
| Related URL |
17557 (SecurityFocus) |
| Related URL |
25920 (ISS) |
|