CVSS Base Vector:
Multiple flaws are due to:
- An error in the 'Config/Container.php', which is not properly validating the
input passed to 'includeFile' parameter.
- An error in the 'fog/lib/pear/HTML/QuickForm.php', which is not properly
validating the input passed to 'includeFile' parameter.
- An error in the 'fog/lib/pear/DB/NestedSet.php', which is not properly
validating the input passed to 'driverpath' parameter.
- An error in the 'fog/lib/pear/DB/NestedSet/Output.php', which is not properly
validating the input passed to 'path' parameter.
- An SQL injection error in 'index.php', which allows remote attackers to
execute arbitrary SQL commands via the frmQuestion parameter in a retrieve
action, in conjunction with a user/password PATH_INFO.
No known solution was made available for at least one year since the disclosure
of this vulnerability. Likely none will be provided anymore. General solution options are to upgrade to a newer
release, disable respective features, remove the product or replace the product by another one.
This host is running Seagull and is prone to SQL injection and
multiple remote file inclusion vulnerabilities.
Successful exploitation will allow attacker to execute arbitrary
code on the vulnerable Web server and to execute arbitrary SQL commands.
Seagull version 0.6.7
Vendor will not fix
NIST (National Institute of Standards and Technology) NVD (National Vulnerability Database)