OCPortal Content Management System Remote File Include Vulnerability
BID:11368
Info
OCPortal Content Management System Remote File Include Vulnerability
| Bugtraq ID: | 11368 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2004 12:00AM |
| Updated: | Oct 12 2004 12:00AM |
| Credit: | Disclosure of this issue is credited to Exoduks <[email protected]>. |
| Vulnerable: |
ocPortal Web Content Management System 1.0.3 ocPortal Web Content Management System 1.0.2 ocPortal Web Content Management System 1.0.1 ocPortal Web Content Management System 1.0 |
| Not Vulnerable: |
ocPortal Web Content Management System 2.0 ocPortal Web Content Management System 1.0.4 |
Discussion
OCPortal Content Management System Remote File Include Vulnerability
Reportedly ocPortal is affected by a remote file include vulnerability. This issue is due to a failure of the application to sanitize user supplied URI input.
An attacker might leverage this issue to run arbitrary server side script code on a vulnerable computer with the privileges of the web server process. This may potentially result in a compromise of the vulnerable computer as well as other attacks.
Reportedly ocPortal is affected by a remote file include vulnerability. This issue is due to a failure of the application to sanitize user supplied URI input.
An attacker might leverage this issue to run arbitrary server side script code on a vulnerable computer with the privileges of the web server process. This may potentially result in a compromise of the vulnerable computer as well as other attacks.
Exploit / POC
OCPortal Content Management System Remote File Include Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
OCPortal Content Management System Remote File Include Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
ocPortal Web Content Management System 1.0
ocPortal Web Content Management System 1.0.1
ocPortal Web Content Management System 1.0.2
ocPortal Web Content Management System 1.0.3
Solution:
The vendor has released an upgrade dealing with this issue.
ocPortal Web Content Management System 1.0
-
ocPortal ocPortal 2.0
http://ocportal.com/dload.php?id=32
ocPortal Web Content Management System 1.0.1
-
ocPortal ocPortal 2.0
http://ocportal.com/dload.php?id=32
ocPortal Web Content Management System 1.0.2
-
ocPortal ocPortal 2.0
http://ocportal.com/dload.php?id=32
ocPortal Web Content Management System 1.0.3
-
ocPortal ocPortal 2.0
http://ocportal.com/dload.php?id=32
References
OCPortal Content Management System Remote File Include Vulnerability
References:
References:
- ocPortal Home Page (ocPortal)
- [hackgen-2004-#002] - Remote file inclusion bug in ocPortal 1.0.3. (Exoduks
)