News Feed
Jobs Feed
Sections

Recent Jobs

News Archive
Secunia.com:
CodeIgniter Weakness and Directory Traversal Vulnerability
July 11, 2007 @ 11:07:00

On the Secunia.com site today, there's a new vulnerability posted that users of the CodeIgniter framework should pay attention to - a "weakness and directory traversal vulnerability".

Lukasz Pilorz has reported a vulnerability and a weakness in CodeIgniter, which can be exploited by malicious people to disclose sensitive information and conduct cross-site scripting and header injection attacks.

There are two problems that lead to this issue - a non-sanitized input parameter and unsanitized data being passed to the xss_clean function. These issues affect CodeIgniter version 1.5.3 and, as of the time of this post, no update has been made in an official release. It is mentioned, however, that the problem has been fixed in the CVS and is waiting for a release.

0 comments voice your opinion now!
codeigniter weakness directory traversal vulnerability framework codeigniter weakness directory traversal vulnerability framework



Similar Posts

The Bakery: File Uploads, TuneShout.com, Zip Files and Uuid Behavior

Soledad Pendaes' Blog: PHP will never have a (real) Rails-like framework

RelativeSanity.com: The Problem with PHP

Secunia.com: CodeIgniter Weakness and Directory Traversal Vulnerability

Debuggable Blog: Amazon Associates API (data source) for CakePHP


Community Events







Don't see your event here?
Let us know!


package book example release conference security ajax zend PEAR zendframework code developer job application releases database mysql cakephp PHP5 framework

All content copyright, 2008 PHPDeveloper.org :: info@phpdeveloper.org - Powered by the Solar PHP Framework