FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

phpwebftp -- "language" Local File Inclusion

Affected packages
phpwebftp < 3.3

Details

VuXML ID d9dc2697-dadf-11da-912f-00123ffe8333
Discovery 2006-04-18
Entry 2006-05-03

Secunia reports:

phpWebFTP have a vulnerability, which can be exploited by malicious people to disclose sensitive information.

Input passed to the "language" parameter in index.php isn't properly verified, before it is used to include files. This can be exploited to include arbitrary files from local resources.

Successful exploitation requires that "magic_quotes_gpc" is disabled.

References

CVE Name CVE-2006-1812
CVE Name CVE-2006-1813
URL http://secunia.com/advisories/19706/
URL https://sourceforge.net/forum/forum.php?forum_id=566199