SiteDepth CMS <= 3.01 - Remote File Include Vulnerability
SecurityAlert : 1256 CVE : CVE-2006-3793 SecurityRisk : High (About) Remote Exploit : Yes Local Exploit : No Exploit Available : No Credit : David "Aesthetico" Vieira-Kurz Published : 25.07.2006
Affected Software :
SiteDepth CMS 3.01 and prior
Advisory Content :
[MajorSecurity #20]SiteDepth CMS <= 3.01 - Remote File Include
Vulnerability
SiteDepth is the most powerful adult paysite CMS on the market!
Requirements:
-------------------------------
register_globals = On
Vulnerability:
-------------------------------
Input passed to the "SD_DIR" parameter in "constants.php" is not
properly verified, before it is used to include files.
This can be exploited to execute arbitrary code by including files from
external resources.
Solution:
-------------------------------
Edit the source code to ensure that input is properly sanitised.
Set "register_globals" to "Off".
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.