HTTP: phpMyNewsletter Insecure File Include

This signature detects attempts to exploit a known vulnerability in phpMyNewsletter. Version 0.6.10 and earlier are vulnerable. phpMyNewsletter does not verify the legitimacy of files included in the customize.php script using the l parameter. Attackers can include a malicious remote file in the customize.php script to execute arbitrary commands on the host.

Extended Description

Remote attackers could exploit this vulnerability to view files on an affected server, or to execute arbitrary commands within the security context of the phpMyNewsLetter process.

Short Name
HTTP:PHP:PHPMYNEWS-INCLUDE
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
File Include Insecure phpMyNewsletter
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?