toendaCMS Admin.PHP Directory Traversal Vulnerability
BID:15348
Info
toendaCMS Admin.PHP Directory Traversal Vulnerability
| Bugtraq ID: | 15348 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 07 2005 12:00AM |
| Updated: | Nov 07 2005 12:00AM |
| Credit: | Bernhard Mueller <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
toendaCMS toendaCMS 0.6.1 |
| Not Vulnerable: |
toendaCMS toendaCMS 0.6.2 |
Discussion
toendaCMS Admin.PHP Directory Traversal Vulnerability
toendaCMS is reported prone to a directory traversal vulnerability. It is demonstrated that this issue may be leveraged to disclose the contents of arbitrary web-server readable files.
A remote attacker may exploit this vulnerability to reveal files that contain potentially sensitive information.
Version 2.1 is vulnerable; earlier versions may also be vulnerable.
toendaCMS is reported prone to a directory traversal vulnerability. It is demonstrated that this issue may be leveraged to disclose the contents of arbitrary web-server readable files.
A remote attacker may exploit this vulnerability to reveal files that contain potentially sensitive information.
Version 2.1 is vulnerable; earlier versions may also be vulnerable.
Exploit / POC
toendaCMS Admin.PHP Directory Traversal Vulnerability
No exploit is required.
The following URI has been provided as an example:
http://www.example.com/engine/admin/admin.php?id_user=
../../../../../../etc/passwd
No exploit is required.
The following URI has been provided as an example:
http://www.example.com/engine/admin/admin.php?id_user=
../../../../../../etc/passwd
Solution / Fix
toendaCMS Admin.PHP Directory Traversal Vulnerability
Solution:
Version 0.6.2 is available to resolve this issue.
toendaCMS toendaCMS 0.6.1
Solution:
Version 0.6.2 is available to resolve this issue.
toendaCMS toendaCMS 0.6.1
-
toendaCMS toendaCMS_0.6.2_Stable.zip
http://www.toenda.com/de/data/files/Software/toendaCMS_Version_0.6.0_S table/toendaCMS_0.6.2_Stable.zip
References
toendaCMS Admin.PHP Directory Traversal Vulnerability
References:
References:
- toendaCMS Web Site (toendaCMS)
- SEC Consult SA-20051107-0 :: toendaCMS multiple vulnerabilites (Bernhard Mueller
)