phpGroupWare Unspecified Remote File Inclusion

high Nessus Plugin ID 14294

Synopsis

Arbitrary code may be run on the remote host.

Description

The version of PhpGroupWare hosted on the remote web server has a vulnerability that may permit remote attackers, without prior authentication, to include and execute malicious PHP scripts.

Remote users may influence URI variables to include a malicious PHP script on a remote system, it is possible to cause arbitrary PHP code to be executed.

Solution

Update to phpGroupWare version 0.9.14.006 or later.

Plugin Details

Severity: High

ID: 14294

File Name: phpgroupware_remote_file_include.nasl

Version: 1.22

Type: remote

Family: CGI abuses

Published: 8/17/2004

Updated: 6/4/2024

Configuration: Enable thorough checks

Supported Sensors: Nessus

Enable CGI Scanning: true

Vulnerability Information

CPE: cpe:/a:phpgroupware:phpgroupware

Excluded KB Items: Settings/disable_cgi_scanning

Exploit Available: true

Exploit Ease: No exploit is required

Reference Information

BID: 8265