Pearl Forums index.php file include

pearl-forums-index-file-include (23196) The risk level is classified as MediumMedium Risk

Description:

Pearl Forums could allow a remote attacker to include malicious PHP files. A remote attacker could send a specially-crafted URL to the index.php script using the mode parameter to include malicious PHP code from the local system which would enable the attacker to execute arbitrary code on the vulnerable system.


Consequences:

Gain Access

Remedy:

No remedy available as of July 9, 2011.

References:

  • Pearl Forums Web site: Pearlinger.
  • BID-15433: Pearl Forums Index.PHP Local File Include Vulnerability
  • CVE-2005-4646: Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files via the mode parameter, possibly due to a directory traversal vulnerability. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
  • OSVDB ID: 20849: Pearl Forums index.php mode Variable Local File Inclusion
  • SA17533: Pearl Forums SQL Injection and Local File Inclusion Vulnerabilities
  • VUPEN/ADV-2005-2426: Pearl Forums Remote SQL Injection and Directory Traversal Issues

Platforms Affected:

  • Pearl Forums Pearl Forums 2.4
  • Pearlinger PearlForums 2.0

Reported:

Nov 15, 2005

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (IBM Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

For corrections or additions please email xforce@iss.net

Return to the main page