____________________ ___ ___ ________ \_ _____/\_ ___ \ / | \\_____ \ | __)_ / \ \// ~ \/ | \ | \\ \___\ Y / | \ /_______ / \______ /\___|_ /\_______ / \/ \/ \/ \/ .OR.ID ECHO_ADV_77$2007 ----------------------------------------------------------------------------------------- [ECHO_ADV_77$2007] Study planner (Studiewijzer) <= 0.15 Remote File Inclusion Vulnerability ----------------------------------------------------------------------------------------- Author : M.Hasran Addahroni Date : March, 21th 2007 Location : Australia, Sydney Web : http://advisories.echo.or.id/adv/adv77-K-159-2007.txt Critical Lvl : Dangerous Impact : System access Where : From Remote --------------------------------------------------------------------------- Affected software description: ~~~~~~~~~~~~~~~~~~~~~~~~~~~ Application : Study planner (Studiewijzer) version : <= 0.15 Vendor : http://www.studiewijzer.nl/ http://sourceforge.net/projects/splanner Description : A study planner, helping students to choose and plan the appropriate actions or tasks in order to reach their goals (PHP based) --------------------------------------------------------------------------- Vulnerability: ~~~~~~~~~~~~~ - Invalid include function at inc/service.alert.inc.php : ----------------inc/service.alert.inc.php-------------------