ocPortal req_path file include
| ocportal-reqpath-file-include (17699) |
Description:
ocPortal could allow a remote attacker to include malicious PHP files. A remote attacker could send a specially-crafted URL request to the index.php script using the $req_path variable to specify a malicious file from a remote system, which would allow the attacker to execute code on the vulnerable system.
Consequences:
Gain Access
Remedy:
Upgrade to the latest version of ocPortal (1.0.4 or later), available from the ocPortal Web site. See References.
References:
- BugTraq Mailing List, Tue Oct 12 2004 - 07:04:02 CDT : [hackgen-2004-#002] - Remote file inclusion bug in ocPortal 1.0.3..
- ocPortal Web site: ocPortal - The best community CMS/Portal solution.
- BID-11368: OCPortal Content Management System Remote File Include Vulnerability
- CVE-2004-1592: PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code by modifying the req_path parameter to reference a URL on a remote web server that contains a malicious funcs.php script.
- SA12811: ocPortal "index.php" Arbitrary File Inclusion Vulnerability
Platforms Affected:
- ocProducts ocPortal 1.0.3
Reported:
Oct 13, 2004
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
For corrections or additions please email xforce@iss.net
