Description
|
|
A vulnerability has been identified in various Harland products, which could be exploited by attackers to compromise a vulnerable web server. This issue is caused by input validation errors in the administrative interface that does not validate user-supplied data before being written to a script, which could be exploited by remote attackers to inject and execute arbitrary PHP code with the privileges of the web server.
|
|
|
|
Vulnerable Products
|
|
Vulnerable Software: Harland Traffic Click 4 Cash ScriptHarland Get A Date ScriptHarland Birthsake KeepsakeHarland FFAHarland TShirt Rental ScriptHarland Mug Rental scriptHarland Top HitsHarland Recipe 6.0Harland Link Lister Traffic SystemHarland Link Back Checker Service ScriptHarland AD PHP Script
|
|
|
|
Solution
|
|
|
|
|
|
CVE
|
|
|
|
|
|
References
|
|
http://www.milw0rm.com/exploits/8699
|
|
|
|
Vulnerability Manager Detection
|
|
No
|
|
|
|
IPS Protection
|
|
|
|
|
|