SAMATE Logo NIST Logo The SAMATE Project Department of Homeland Security
Downloads:  Download this Test Case #1949

Back to the previous page... Back to the previous page

Test Case IDCandidate1949
Bad / Good / MixedBadBad test case
Author
Associations
Test suite: 31  
Added byRomain Gaucher
LanguagePHP
Type of test caseSource Code
Input string
Expected Output
Instructions
Submission date2007-03-13
DescriptionThe test case shows a PHP Include Vulnerability. A defense mechanism use the file_exists function and the configuration of PHP may allow the file_exists to return true with distant files, this may allow a Remote File Inclusion.
File(s)
Flaw

There are no comments
Have any comments on this test case? Please, .


					
				

					
				
File Contains:
CWE-098: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') on line(s): 14