GuppY Error.PHP Remote File Include and Command Execution Vulnerability
BID:15609
Info
GuppY Error.PHP Remote File Include and Command Execution Vulnerability
| Bugtraq ID: | 15609 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3926 CVE-2007-5845 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 28 2005 12:00AM |
| Updated: | Nov 15 2007 12:36AM |
| Credit: | Discovered by rgod. |
| Vulnerable: |
Guppy GuppY 4.5.16 Guppy GuppY 4.5.9 Guppy GuppY 4.5.4 Guppy GuppY 4.5.3 a Guppy GuppY 4.5.3 Guppy GuppY 4.5 |
| Not Vulnerable: | |
Discussion
GuppY Error.PHP Remote File Include and Command Execution Vulnerability
GuppY is prone to a remote file-include vulnerability and to a command-execution vulnerability.
The software fails to properly sanitize data supplied to the 'error.php' script, allowing attackers to specify remotely hosted script files to be executed in the context of the webserver hosting the vulnerable software.
An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the webserver process.
An attacker can also pass malicious PHP commands through this script to be executed on an affected server, which could facilitate unauthorized access as well.
GuppY 4.5.16 and prior versions are vulnerable.
GuppY is prone to a remote file-include vulnerability and to a command-execution vulnerability.
The software fails to properly sanitize data supplied to the 'error.php' script, allowing attackers to specify remotely hosted script files to be executed in the context of the webserver hosting the vulnerable software.
An attacker can exploit this issue to execute arbitrary remote PHP code on an affected computer with the privileges of the webserver process.
An attacker can also pass malicious PHP commands through this script to be executed on an affected server, which could facilitate unauthorized access as well.
GuppY 4.5.16 and prior versions are vulnerable.
Exploit / POC
GuppY Error.PHP Remote File Include and Command Execution Vulnerability
An exploit is not required.
Proof-of-concept examples are available:
http://www.example.com/[path_to_guppy]/error.php?err=hacker&_SERVER=&_SERVER[REMOTE_ADDR]=";passthru("ls -la>README");echo"
An exploit is not required.
Proof-of-concept examples are available:
http://www.example.com/[path_to_guppy]/error.php?err=hacker&_SERVER=&_SERVER[REMOTE_ADDR]=";passthru("ls -la>README");echo"
Solution / Fix
GuppY Error.PHP Remote File Include and Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
GuppY Error.PHP Remote File Include and Command Execution Vulnerability
References:
References: