Bee-hive Multiple Remote File Include Vulnerabilities
BID:18654
CVE-2006-3266 |Info
Bee-hive Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 18654 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 16 2006 12:00AM |
| Updated: | Jun 27 2006 04:20AM |
| Credit: | Kw3[R]Ln is credited with discovering this vulnerability. |
| Vulnerable: |
MagNet Bee-hive 1.2 |
| Not Vulnerable: | |
Discussion
Bee-hive Multiple Remote File Include Vulnerabilities
Bee-hive is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input to the application.
An attacker may leverage these issues to have an arbitrary remote file containing malicious script code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.
These issues affect version 1.2; other versions may also be vulnerable.
Bee-hive is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input to the application.
An attacker may leverage these issues to have an arbitrary remote file containing malicious script code execute in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system. Other attacks are also possible.
These issues affect version 1.2; other versions may also be vulnerable.
Exploit / POC
Bee-hive Multiple Remote File Include Vulnerabilities
These vulnerabilities can be exploited using a web browser.
The following proof-of-concept URIs are available:
These vulnerabilities can be exploited using a web browser.
The following proof-of-concept URIs are available:
Solution / Fix
Bee-hive Multiple Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please email us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please email us at: [email protected]:[email protected].
References
Bee-hive Multiple Remote File Include Vulnerabilities
References:
References:
- Bee-hive Homepage (MagNet)
- Beehive CMS ([header]) Remote File Include Vulnerabilities (Kw3[R]Ln)