I-RATER Platinum 的admin/config_settings.tpl.php存在PHP远程文件包含漏洞,远程攻击者可以通过在include_path 参数中的URL执行任意代码。
来源: BID
名称: 17731
链接:http://www.securityfocus.com/bid/17731
来源: BUGTRAQ
名称: 20060429 I-RATER Platinum Remote File Inclusion exploit Cod3d by R@1D3N
链接:http://www.securityfocus.com/archive/1/archive/1/432596/100/0/threaded
来源: XF
名称: irater-configsettingtpl-file-include(26203)
链接:http://xforce.iss.net/xforce/xfdb/26203
来源: BUGTRAQ
名称: 20060428 [Kurdish Secure Advisory #1] I-RATER Platinum "Admin/configsettings.tpl.php" Remote File Include Vulnerability
链接:http://www.securityfocus.com/archive/1/archive/1/432404/100/0/threaded
来源: SREASON
名称: 824
链接:http://securityreason.com/securityalert/824
暂无
发布时间 Feb 2, 2009
发布时间 Apr 20, 2006