Jetbox CMS Config.PHP Remote File Include Vulnerability
BID:17861
Info
Jetbox CMS Config.PHP Remote File Include Vulnerability
| Bugtraq ID: | 17861 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-2270 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2006 12:00AM |
| Updated: | Mar 08 2007 03:15AM |
| Credit: | beford is credited with the discovery of this vulnerability. |
| Vulnerable: |
Jetbox Jetbox CMS 2.1 |
| Not Vulnerable: | |
Discussion
Jetbox CMS Config.PHP Remote File Include Vulnerability
Jetbox CMS is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue appears to affect code that is shared by PhpDig, but the discoverer of the vulnerability has stated that the issue has been fixed in PhpDig. It is not known which versions of PhpDig are affected. After further analysis, this issue may be determined to be a PhpDig vulnerability.
Jetbox CMS is prone to a remote file-include vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
This issue appears to affect code that is shared by PhpDig, but the discoverer of the vulnerability has stated that the issue has been fixed in PhpDig. It is not known which versions of PhpDig are affected. After further analysis, this issue may be determined to be a PhpDig vulnerability.
Exploit / POC
Jetbox CMS Config.PHP Remote File Include Vulnerability
Attackers can exploit this issue via a web client.
The following exploit is available:
Attackers can exploit this issue via a web client.
The following exploit is available:
Solution / Fix
Jetbox CMS Config.PHP Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
Jetbox CMS Config.PHP Remote File Include Vulnerability
References:
References:
- Jetbox CMS Homepage (Jetbox)
- JetBox CMS Remote File Include (beford
) - Multible injections and vulnerabilities in Jetbox CMS ( HACKERS PAL & mohajali)