CVE-2010-1335 Information

Description

Multiple PHP remote file inclusion vulnerabilities in Insky CMS 006-0111 when register_globals is enabled allow remote attackers to execute arbitrary PHP code via a URL in the ROOT parameter to (1) city.get/city.get.php (2) city.get/index.php (3) message2.send/message.send.php (4) message.send/message.send.php and (5) pages.add/pages.add.php in insky/modules/. NOTE: some of these details are obtained from third party information.

Reference

http://osvdb.org/63149 http://osvdb.org/63150 http://osvdb.org/63151 http://osvdb.org/63152 http://osvdb.org/63153 http://packetstormsecurity.org/1003-exploits/inskycms-rfi.txt http://secunia.com/advisories/39112 http://www.exploit-db.com/exploits/11848 https://exchange.xforce.ibmcloud.com/vulnerabilities/57112

Share on: