OSCommerce Update.PHP Information Disclosure Vulnerability
BID:14294
Info
OSCommerce Update.PHP Information Disclosure Vulnerability
| Bugtraq ID: | 14294 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2005 12:00AM |
| Updated: | Apr 17 2006 11:32PM |
| Credit: | Andrew Hunter <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
osCommerce osCommerce 2.2 ms2 |
| Not Vulnerable: | |
Discussion
OSCommerce Update.PHP Information Disclosure Vulnerability
osCommerce is prone to an information-disclosure vulnerability. An attacker could exploit this vulnerability to display the contents of any file normally readable by the webserver process.
Successful exploitation would result in information disclosure. Information obtained could aid the attacker in further attacks against the underlying system; other attacks are also possible.
This issue reportedly affects osCommerce version 2.2 milestone 2; other versions may also be vulnerable.
osCommerce is prone to an information-disclosure vulnerability. An attacker could exploit this vulnerability to display the contents of any file normally readable by the webserver process.
Successful exploitation would result in information disclosure. Information obtained could aid the attacker in further attacks against the underlying system; other attacks are also possible.
This issue reportedly affects osCommerce version 2.2 milestone 2; other versions may also be vulnerable.
Exploit / POC
OSCommerce Update.PHP Information Disclosure Vulnerability
No exploit is required.
The following proof-of-concept URIs are available:
http://www.example.com/catalog/extras/update.php?readme_file=/etc/passwd
http://www.example.com/catalog/extras/update.php?readme_file=../admin/.htaccess
No exploit is required.
The following proof-of-concept URIs are available:
http://www.example.com/catalog/extras/update.php?readme_file=/etc/passwd
http://www.example.com/catalog/extras/update.php?readme_file=../admin/.htaccess
Solution / Fix
OSCommerce Update.PHP Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
References
OSCommerce Update.PHP Information Disclosure Vulnerability
References:
References:
- osCommerce <= 2.2 extras/ information/source code disclosure (rgod)
- osCommerce Homepage (osCommerce)
- osCommerce extras/ information/source code disclosure (rgod)
- RE: osCommerce extras/ information/source code disclosure (Michael Scheidell)