Yawp Conf_Path Remote File Include Vulnerability
BID:14237
Info
Yawp Conf_Path Remote File Include Vulnerability
| Bugtraq ID: | 14237 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Jul 12 2005 12:00AM |
| Credit: | Stefan Esser <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
Yawp Yawp 1.0.6 |
| Not Vulnerable: |
Yawp Yawp 1.1 |
Discussion
Yawp Conf_Path Remote File Include Vulnerability
Yawp is affected by a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
It should be noted even with 'register_globals' and 'allow_url_fopen' turned on in the local PHP configuration, this vulnerability can still be exploited when utilizing PHP5.
Yawp is affected by a remote file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
It should be noted even with 'register_globals' and 'allow_url_fopen' turned on in the local PHP configuration, this vulnerability can still be exploited when utilizing PHP5.
Exploit / POC
Yawp Conf_Path Remote File Include Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Yawp Conf_Path Remote File Include Vulnerability
Solution:
The vendor has addressed this issue in Yawp version 1.1.0:
Yawp Yawp 1.0.6
Solution:
The vendor has addressed this issue in Yawp version 1.1.0:
Yawp Yawp 1.0.6
-
Yawp Yawp-1.1.0.tgz
http://phpyawp.com/Yawp-1.1.0.tgz
References
Yawp Conf_Path Remote File Include Vulnerability
References:
References:
- YaWiki Homepage (YaWiki)
- Yawp Homepage (Yawp)
- Advisory 10/2005: Yawp/YaWiki Remote URL Include Vulnerability (Stefan Esser
)