HTTP: myphpPageTool Remote Include

This signature detects attempts to exploit a SQL injection vulnerability in MyphpPageTool. phpMyShop 1.00 and earlier versions are vulnerable. Attackers can submit a maliciously crafted URL to cause the Web server to execute arbitrary PHP code.

Extended Description

This vulnerability enables an adversary to execute arbitrary PHP code, with the privilege level of the web service account, which is usually the "nobody" user. This capability could be leveraged to completely compromise the myphpPageTool installation by overwriting database tables and configuration files.

Short Name
HTTP:PHP:PAGETOOL-SQL-INJ
Severity
Warning
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Include Remote myphpPageTool
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?