PHPRaid PHPRAID_DIR Parameter Multiple Remote File Include Vulnerabilities
BID:18719
CVE-2006-3116 | CVE-2006-3316 | CVE-2006-3317 |Info
PHPRaid PHPRAID_DIR Parameter Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 18719 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 29 2006 12:00AM |
| Updated: | Jun 29 2006 06:39PM |
| Credit: | These issues were discovered by Sven Krewitt, Secunia Research. |
| Vulnerable: |
phpRaid phpRaid 3.0.5 phpRaid phpRaid 3.0.4 |
| Not Vulnerable: | |
Discussion
PHPRaid PHPRAID_DIR Parameter Multiple Remote File Include Vulnerabilities
The phpRaid application is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
The phpRaid application is prone to multiple remote file-include vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Exploit / POC
PHPRaid PHPRAID_DIR Parameter Multiple Remote File Include Vulnerabilities
These issues can be exploited through a web client.
These issues can be exploited through a web client.
Solution / Fix
PHPRaid PHPRAID_DIR Parameter Multiple Remote File Include Vulnerabilities
Solution:
The vendor has released version 3.0.6 to address these issues. Please contact the vendor to obtain fixes.
Solution:
The vendor has released version 3.0.6 to address these issues. Please contact the vendor to obtain fixes.
References
PHPRaid PHPRAID_DIR Parameter Multiple Remote File Include Vulnerabilities
References:
References:
- phpRaid Homepage (phpRaid)
- phpRaid SQL Injection and File Inclusion Vulnerabilities (Secunia)