phpMyFAQ Action Parameter Arbitrary File Disclosure Vulnerability
BID:10374
Info
phpMyFAQ Action Parameter Arbitrary File Disclosure Vulnerability
| Bugtraq ID: | 10374 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 18 2004 12:00AM |
| Updated: | May 18 2004 12:00AM |
| Credit: | Discovery is credited to Stefan Esser <[email protected]>. |
| Vulnerable: |
phpMyFAQ phpMyFAQ 1.3.12 |
| Not Vulnerable: |
phpMyFAQ phpMyFAQ 1.3.13 |
Discussion
phpMyFAQ Action Parameter Arbitrary File Disclosure Vulnerability
phpMyFAQ is prone to an arbitrary file disclosure vulnerability that can allow a remote attacker to gain access to potentially sensitive information. This vulnerability exists due to insufficient sanitization of user-supplied data via the 'action' parameter. An attacker can disclose files by passing a relative path to a file and concatenating the path with a '\0' string terminator.
phpMyFAQ version 1.3.12 is prone to this issue.
phpMyFAQ is prone to an arbitrary file disclosure vulnerability that can allow a remote attacker to gain access to potentially sensitive information. This vulnerability exists due to insufficient sanitization of user-supplied data via the 'action' parameter. An attacker can disclose files by passing a relative path to a file and concatenating the path with a '\0' string terminator.
phpMyFAQ version 1.3.12 is prone to this issue.
Exploit / POC
phpMyFAQ Action Parameter Arbitrary File Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
phpMyFAQ Action Parameter Arbitrary File Disclosure Vulnerability
Solution:
phpMyFAQ 1.1.13 is availabe to address this issue:
phpMyFAQ phpMyFAQ 1.3.12
Solution:
phpMyFAQ 1.1.13 is availabe to address this issue:
phpMyFAQ phpMyFAQ 1.3.12
-
phpMyFAQ phpMyFAQ 1.1.13
http://www.phpmyfaq.de/getfaq.php?number=1.3.13&version=full
References
phpMyFAQ Action Parameter Arbitrary File Disclosure Vulnerability
References:
References:
- phpMyFAQ Homepage (phpMyFAQ)
- Advisory 05/2004: phpMyFAQ local file inclusion vulnerability (Stefan Esser
)