PHPWebSite Index.PHP Directory Traversal Vulnerability
BID:14166
Info
PHPWebSite Index.PHP Directory Traversal Vulnerability
| Bugtraq ID: | 14166 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 06 2005 12:00AM |
| Updated: | Jul 06 2005 12:00AM |
| Credit: | Diabolic Crab is credited with the discovery of this vulnerability. |
| Vulnerable: |
phpWebsite phpWebsite 0.10.1 phpWebsite phpWebsite 0.10 phpWebsite phpWebsite 0.9.3 -4 phpWebsite phpWebsite 0.9.3 -3 phpWebsite phpWebsite 0.9.3 -2 phpWebsite phpWebsite 0.9.3 -1 phpWebsite phpWebsite 0.9.3 phpWebsite phpWebsite 0.8.3 phpWebsite phpWebsite 0.8.2 phpWebsite phpWebsite 0.7.3 |
| Not Vulnerable: | |
Discussion
PHPWebSite Index.PHP Directory Traversal Vulnerability
phpWebSite is affected by a directory traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
A remote unauthorized user can disclose the contents of arbitrary local files through the use of directory traversal strings '../'. Exploitation of this vulnerability could lead to a loss of confidentiality.
The vendor has released the patch phpwebsite_security_patch_20050705.2.tgz addressing this issue.
phpWebSite is affected by a directory traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
A remote unauthorized user can disclose the contents of arbitrary local files through the use of directory traversal strings '../'. Exploitation of this vulnerability could lead to a loss of confidentiality.
The vendor has released the patch phpwebsite_security_patch_20050705.2.tgz addressing this issue.
Exploit / POC
PHPWebSite Index.PHP Directory Traversal Vulnerability
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/phpwebsite/index.php?module=search&search_op=search&mod=../../../../../../../../etc/passwd%00&query=1&search=Search
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/phpwebsite/index.php?module=search&search_op=search&mod=../../../../../../../../etc/passwd%00&query=1&search=Search
Solution / Fix
PHPWebSite Index.PHP Directory Traversal Vulnerability
Solution:
The vendor has released a patch addressing this issue.
Gentoo has released advisory GLSA 200507-07 to address this issue in phpWebSite. Please see the referenced advisory for more information. Gentoo recommends all phpWebSite users should upgrade to the latest available version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-app/phpwebsite-0.10.1-r1"
phpWebsite phpWebsite 0.10
phpWebsite phpWebsite 0.10.1
phpWebsite phpWebsite 0.9.3 -4
phpWebsite phpWebsite 0.9.3 -2
phpWebsite phpWebsite 0.9.3 -3
Solution:
The vendor has released a patch addressing this issue.
Gentoo has released advisory GLSA 200507-07 to address this issue in phpWebSite. Please see the referenced advisory for more information. Gentoo recommends all phpWebSite users should upgrade to the latest available version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-app/phpwebsite-0.10.1-r1"
phpWebsite phpWebsite 0.10
-
phpWebsite phpwebsite_security_patch_20050705.2.tgz
http://phpwebsite.appstate.edu/downloads/security/phpwebsite_security_ patch_20050705.2.tgz
phpWebsite phpWebsite 0.10.1
-
phpWebsite phpwebsite_security_patch_20050705.2.tgz
http://phpwebsite.appstate.edu/downloads/security/phpwebsite_security_ patch_20050705.2.tgz
phpWebsite phpWebsite 0.9.3 -4
-
phpWebsite phpwebsite_security_patch_20050705.2.tgz
http://phpwebsite.appstate.edu/downloads/security/phpwebsite_security_ patch_20050705.2.tgz
phpWebsite phpWebsite 0.9.3 -2
-
phpWebsite phpwebsite_security_patch_20050705.2.tgz
http://phpwebsite.appstate.edu/downloads/security/phpwebsite_security_ patch_20050705.2.tgz
phpWebsite phpWebsite 0.9.3 -3
-
phpWebsite phpwebsite_security_patch_20050705.2.tgz
http://phpwebsite.appstate.edu/downloads/security/phpwebsite_security_ patch_20050705.2.tgz