Skip to content

J-Security Center

Latest Attack Object Updates
  • IDP Daily Update #1375
    posted: 02/27/09
  • NSM Daily Update #1375
    posted: 02/27/09
  • Deep Inspection 5.3r5 and above, 5.4, 6.0 #1375
    posted: 02/27/09
  • Deep Inspection 5.1, 5.2, 5.3r4 and below #1361
    posted: 02/27/09
  • Deep Inspection 5.0 #1132
    posted: 04/01/08
  • Antivirus
    posted: 02/26/09

Title: Thyme 'export.php' Local File Include Vulnerability

Severity: HIGH

Description:

Thyme is a PHP-based photo calendar application.

The application is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input to the 'export_to' parameter of the 'export.php' script.

An attacker can exploit this vulnerability to view and execute arbitrary local files in the context of the webserver process. This may aid in further attacks.

Thyme 1.3 is vulnerable; other versions may also be affected

Affected Products:

  • EXtrovert Software Thyme 1.3

References: