make the description a little more descriptive.

git-svn-id: file:///home/svn/framework3/trunk@9611 4d416f70-5f16-0410-b530-b9f4589650da
unstable
James Lee 2010-06-24 18:34:37 +00:00
parent 32fa35d53f
commit e47f38365d
1 changed files with 6 additions and 4 deletions

View File

@ -20,10 +20,12 @@ class Metasploit3 < Msf::Exploit::Remote
super(update_info(info,
'Name' => 'TikiWiki tiki-graph_formula Remote PHP Code Execution',
'Description' => %q{
TikiWiki (<= 1.9.8) contains a flaw that may allow a remote attacker to execute arbitrary commands.
The issue is due to 'tiki-graph_formula.php' script not properly sanitizing user input
supplied to the f variable, which may allow a remote attacker to execute arbitrary PHP
code resulting in a loss of integrity.
TikiWiki (<= 1.9.8) contains a flaw that may allow a remote
attacker to execute arbitrary PHP code. The issue is due to
'tiki-graph_formula.php' script not properly sanitizing user
input supplied to create_function(), which may allow a remote
attacker to execute arbitrary PHP code resulting in a loss of
integrity.
},
'Author' => [ 'Matteo Cantoni <goony[at]nothink.org>', 'jduck' ],
'License' => MSF_LICENSE,