{"vuid":"VU#391347","idnumber":"391347","name":"phpSecurePages allows remote code execution","keywords":["phpSecurePages","remote command execution","unauthenticated users","user access","interface.php","cfgProgPath","checklogin.php"],"overview":"There is an input validation vulnerability in phpSecurePages that may allow a remote intruder to execute arbitrary code with the privileges of the running web server.","clean_desc":"phpSecurePages is a tool for password protecting portions of websites on PHP enabled webservers. The vulnerability occurs because phpSecurePages makes insecure calls to the PHP function include(). For more detailed information, please see the Secure Reality Advisory.","impact":"A remote intruder can execute arbitrary code on the target host with the privileges of the web server.","resolution":"Versions up to and including Beta 2.4 suffer from this vulnerability. Upgrade to a version above 1.0.5 from http://www.phpsecurepages.com/.","workarounds":"","sysaffected":"","thanks":"This vulnerability was discovered by Shaun Clowes <\nshaun@securereality.com.au\n> and was reported to the Bugtraq mailing list on July 03, 2001.","author":"This document was written by Ian A. Finlay.","public":["http://www.securityfocus.com/bid/2970","http://www.securitytracker.com/alerts/2001/Apr/1001408.html","http://www.phpsecurepages.com/"],"cveids":[""],"certadvisory":"","uscerttechnicalalert":null,"datecreated":"2001-07-05T17:50:27Z","publicdate":"2001-02-07T00:00:00Z","datefirstpublished":"2001-08-09T15:33:00Z","dateupdated":"2004-07-28T15:17:43Z","revision":23,"vrda_d1_directreport":"","vrda_d1_population":"","vrda_d1_impact":"","cam_widelyknown":"20","cam_exploitation":"0","cam_internetinfrastructure":"10","cam_population":"5","cam_impact":"19","cam_easeofexploitation":"20","cam_attackeraccessrequired":"20","cam_scorecurrent":"21.375","cam_scorecurrentwidelyknown":"21.375","cam_scorecurrentwidelyknownexploited":"35.625","ipprotocol":"","cvss_accessvector":"","cvss_accesscomplexity":"","cvss_authentication":null,"cvss_confidentialityimpact":"","cvss_integrityimpact":"","cvss_availabilityimpact":"","cvss_exploitablity":null,"cvss_remediationlevel":"","cvss_reportconfidence":"","cvss_collateraldamagepotential":"","cvss_targetdistribution":"","cvss_securityrequirementscr":"","cvss_securityrequirementsir":"","cvss_securityrequirementsar":"","cvss_basescore":"","cvss_basevector":"","cvss_temporalscore":"","cvss_environmentalscore":"","cvss_environmentalvector":"","metric":21.375,"vulnote":null}