HTTP: Activist Mobilization Platform 3.2 base.php Remote File Inclusion
This signature detects attempts to exploit a known remote file inclusion vulnerability in the Activist Mobilization Platform (AMP) 3.2. It is due to insufficient validation of user-supplied input in base.php script. A remote attacker can exploit this by enticing a target to open a malicious URL link. A successful attack can result in arbitrary code execution and loss of sensitive information.
Extended Description
PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter.
Affected Products
Radical_designs activist_mobilization_platform
References
CVE: CVE-2007-1571
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Radical_designs
6.8