Menu

#52 Security Vulnerability

open
nobody
None
5
2010-03-29
2010-03-29
Andrew
No

There is a vulnerability with the AnyInventory software.

The coding in this software allows hackers to exploit the code and upload files to a webserver.

At least the following files contain unsecure code:

index.php
environment.php
docs/index.php
docs/items.php

The vulnerabilities allow RFI/Code injection.

Other than this the software seems to work well, although we get a 500 internal error if we try to load the page showing all items (with 7000 items in database), so if you can secure it further it is a good web based inventory system.

Discussion


Log in to post a comment.

MongoDB Logo MongoDB