FlatNuke User Data Arbitrary PHP Code Execution Vulnerability
BID:14485
Info
FlatNuke User Data Arbitrary PHP Code Execution Vulnerability
| Bugtraq ID: | 14485 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2005 12:00AM |
| Updated: | Aug 05 2005 12:00AM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
FlatNuke FlatNuke 2.5.5 |
| Not Vulnerable: | |
Discussion
FlatNuke User Data Arbitrary PHP Code Execution Vulnerability
FlatNuke is affected by an arbitrary PHP code execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input recorded during user registration.
An attacker can exploit this vulnerability and supply arbitrary PHP code as part of the user data. The attacker can then call the stored file and have the uncommented code executed in the context of the Web server process. This may aid the attacker in further attacks against the underlying system.
FlatNuke is affected by an arbitrary PHP code execution vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input recorded during user registration.
An attacker can exploit this vulnerability and supply arbitrary PHP code as part of the user data. The attacker can then call the stored file and have the uncommented code executed in the context of the Web server process. This may aid the attacker in further attacks against the underlying system.
Exploit / POC
FlatNuke User Data Arbitrary PHP Code Execution Vulnerability
No exploit is required.
The following exploit has been supplied by rgod:
No exploit is required.
The following exploit has been supplied by rgod:
Solution / Fix
FlatNuke User Data Arbitrary PHP Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
FlatNuke User Data Arbitrary PHP Code Execution Vulnerability
References:
References: