DoceboLMS Connector.PHP Directory Traversal Vulnerability
BID:15742
Info
DoceboLMS Connector.PHP Directory Traversal Vulnerability
| Bugtraq ID: | 15742 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 06 2005 12:00AM |
| Updated: | Dec 06 2005 12:00AM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
Docebo DoceboLMS 2.0.4 Docebo DoceboLMS 2.0.3 Docebo DoceboLMS 2.0.2 |
| Not Vulnerable: |
Docebo DoceboLMS 3.0 Docebo DoceboLMS 2.0.5 |
Discussion
DoceboLMS Connector.PHP Directory Traversal Vulnerability
DoceboLMS is prone to a directory traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the Web server process. Information obtained may aid in further attacks; other attacks are also possible.
DoceboLMS is prone to a directory traversal vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the Web server process. Information obtained may aid in further attacks; other attacks are also possible.
Exploit / POC
DoceboLMS Connector.PHP Directory Traversal Vulnerability
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/addons/fckeditor2rc2/editor/filemanager/browser/default/connectors/php/connector.php?Command=GetFoldersAndFiles&Type=../../../../../../../../&CurrentFolder=
No exploit is required.
The following proof of concept URI is available:
http://www.example.com/addons/fckeditor2rc2/editor/filemanager/browser/default/connectors/php/connector.php?Command=GetFoldersAndFiles&Type=../../../../../../../../&CurrentFolder=
Solution / Fix
DoceboLMS Connector.PHP Directory Traversal Vulnerability
Solution:
The vendor has released a minor and major upgrade to address this issue:
Docebo DoceboLMS 2.0.2
Docebo DoceboLMS 2.0.3
Docebo DoceboLMS 2.0.4
Solution:
The vendor has released a minor and major upgrade to address this issue:
Docebo DoceboLMS 2.0.2
-
DoceboLMS docebo30.zip
http://www.docebolms.org/download.php?type=docs&pb=395&id=48 -
DoceboLMS doceboLMS205.zip
http://www.docebolms.org/download.php?type=docs&pb=321&id=49
Docebo DoceboLMS 2.0.3
-
DoceboLMS docebo30.zip
http://www.docebolms.org/download.php?type=docs&pb=395&id=48 -
DoceboLMS doceboLMS205.zip
http://www.docebolms.org/download.php?type=docs&pb=321&id=49
Docebo DoceboLMS 2.0.4
-
DoceboLMS docebo30.zip
http://www.docebolms.org/download.php?type=docs&pb=395&id=48 -
DoceboLMS doceboLMS205.zip
http://www.docebolms.org/download.php?type=docs&pb=321&id=49
References
DoceboLMS Connector.PHP Directory Traversal Vulnerability
References:
References:
- DoceboLMS 2.0.4 remote commands execution (rgod)
- DoceboLMS Homepage (Docebo)