HTTP: PHProjekt "path_pre" Parameter Remote File Include

This signature detects attempts to exploit a vulnerability in the authform.inc.php script included in the PHProjekt package. Attackers can supply a remote location in the "path_pre" input parameter to force the target to download and execute arbitrary PHP code from the remote location.

Extended Description

Remote attackers could exploit this vulnerability to execute arbitrary code on an affected machine.

Short Name
HTTP:PHP:PHPROJEKT-INC
Severity
Minor
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
"path_pre" File Include PHProjekt Parameter Remote
Release Date
01/11/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?