PHP.iPhotoAlbum.Remote.File.Inclusion

description-logoDescription

It indicates a possible exploit of remote file include vulnerability in iPhotoAlbum software package.


iPhotoAlbum is a dynamic online photo album program written in PHP. A remote php code inclusion vulnerability is reported in it that may allow an attacker to execute arbitrary server side script code on the affected system with privilege of web server process. Due to insufficient sanitization of user input by getpage.php and header.php scripts, an attacker may modify doc_path and set_menu parameters on a HTTP request to getpage.php and header.php scripts respectively to reference a URL on a remote web server that contains the malicious code. An attacker may exploit this to execute arbitrary code on the affected system and gain access to it.

affected-products-logoAffected Products

iPhotoAlbum 1.1

Impact logoImpact

Compromise of the affected system.

recomended-action-logoRecommended Actions

Apply appropriate patch from the vendor if available.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)