漏洞描述
Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to execute arbitrary PHP code via a URL in the homedir parameter to (1) OLE/PPS/File.php, (2) OLE/PPS/Root.php, (3) Spreadsheet/Excel/Writer.php, or (4) OLE/PPS.php in admin/classes/pear/; or (5) Worksheet.php, (6) Parser.php, (7) Workbook.php, (8) Format.php, or (9) BIFFwriter.php in admin/classes/pear/Spreadsheet/Excel/Writer/.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.vupen.comhttp://www.vupen.com/english/advisories/2007/2459↗exchange.xforce.ibmcloud.comhttps://exchange.xforce.ibmcloud.com/vulnerabilities/35284↗osvdb.orghttp://osvdb.org/45791↗osvdb.orghttp://osvdb.org/45799↗osvdb.orghttp://osvdb.org/45794↗osvdb.orghttp://osvdb.org/45796↗osvdb.orghttp://osvdb.org/45793↗osvdb.orghttp://osvdb.org/45797↗osvdb.orghttp://osvdb.org/45795↗osvdb.orghttp://osvdb.org/45798↗osvdb.orghttp://osvdb.org/45792↗