Topic : | phpList Local File Include Vulnerability
|
SecurityAlert : 4901
CVE : CVE-2008-5887
CWE : CWE-20
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : No
Credit : phplist
Published : 14.01.2009
Affected Software : | phplist:phplist:2.10.7 and previous versions
phplist:phplist:2.10.4
phplist:phplist:2.10.3
phplist:phplist:2.10.2
phplist:phplist:2.10.1
phplist:phplist:2.8.12
phplist:phplist:2.8.7
phplist:phplist:2.8.2
phplist:phplist:2.7.2
phplist:phplist:2.7.1
phplist:phplist:2.6.5
phplist:phplist:2.10.5 |
 Advisory Content : phpList is a feature rich newsletter application written in PHP.
phpList has a local file include vulnerability. The vulnerability has
already been exploited.
affected versions: any version up to including 2.10.7
fixed in version 2.10.8
Related links:
www.phplist.com phpList homepage
http://sourceforge.net/projects/phplist Sourceforge Project page.
References :
http://www.securityfocus.com/bid/32841
http://www.securityfocus.com/archive/1/archive/1/499218/100/0/threaded
http://www.phplist.com/?lid=273
http://secunia.com/advisories/33186
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|