. Updated Daily. Editions SDA India   SDA Indonesia
BUSINESS ENTERPRISE SOLUTIONS ARCHITECTURE INFORMATION SECURITY WIRELESS & MOBILITY DATA & STORAGE DEVELOPMENT HARDWARE













News

Tuesday, 8 May 2007

Vulnerabilities in PHPChess Community

 

 

Mahmood Ali in Secunia.com has discovered some vulnerabilities in phpChess Community Edition, which can be exploited by malicious people to disclose sensitive information or to compromise a vulnerable system.

He says, input passed to the 'Root_Path' parameter in skins/phpchess/layout_admin_cfg.php, skins/phpchess/layout_cfg.php, and skins/phpchess/layout_t_top.php is not properly verified before being used to include files. This can be exploited to include arbitrary files from local or external resources. Though successful exploitation requires that 'register_globals' be enabled.

The vulnerabilities are confirmed in version 2.0. Other versions may also be affected.

He says, the solution is to edit the source code to ensure that input is properly verified.

 

Read the Post

 
 
print save email comment

print

save

email

comment

 
 

Search SDA Asia

Free eNewsletter

SDA Asia Magazine Free Download
 
 
 
Copyright @ 2009 SDA Asia Magazine - All Right Reserved Privacy Policy | Terms of Use