LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - News > Syndicated Linux News
User Name
Password
Syndicated Linux News This forum is for the discussion of Syndicated Linux News stories.

Notices


Reply
  Search this Thread
Old 12-29-2006, 11:33 PM   #1
LXer
LXer NewsBot
 
Registered: Dec 2005
Posts: 128,378

Rep: Reputation: 118Reputation: 118
LXer: Yrch! "path" Parameter Handling Remote PHP File Inclusion ...


Published at LXer:

A vulnerability has been identified in Yrch!, which could be exploited by attackers to execute arbitrary commands. This issue is due to an input validation error in the "yrch/plugins/metasearch/plug.inc.php" script that does not validate the "path" parameter, which could be exploited by remote attackers to include malicious PHP scripts and execute arbitrary commands with the privileges of the web server.

Read More...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Hlstats "killLimit" Parameter Handling Remote SQL Query Injection ... LXer Syndicated Linux News 0 12-29-2006 07:54 PM
LXer: Gnu Tar "GNUTYPE_NAMES" Record Handling Directory Traversal ... LXer Syndicated Linux News 0 11-28-2006 05:54 AM
shell script to mount samba share with " " in the remote path dohpaz Programming 2 10-20-2006 02:18 PM
Tip: handling "cannot open shared object file..." sundialsvcs Linux - Newbie 1 03-06-2006 12:57 PM
Cedega and Fat32 (Invalid path "." given for "--use-dos-cwd") bdox Linux - Games 0 03-26-2005 02:48 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - News > Syndicated Linux News

All times are GMT -5. The time now is 10:38 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration