Geeklog Multiple Remote File Include Vulnerabilities
BID:18740
Info
Geeklog Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 18740 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-6225 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2006 12:00AM |
| Updated: | Mar 05 2007 08:25PM |
| Credit: | Kw3[R]Ln discovered these vulnerabilities. |
| Vulnerable: |
Geeklog Geeklog 1.4 sr1 Geeklog Geeklog 1.4.0sr3 Geeklog Geeklog 1.4.0sr2 |
| Not Vulnerable: |
Geeklog Geeklog 1.4.0sr4 |
Discussion
Geeklog Multiple Remote File Include Vulnerabilities
Geeklog is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
The vendor indicates that this issue affects only misconfigured installations done via auto-installers.
Geeklog is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
A successful exploit of these issues allows the attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
The vendor indicates that this issue affects only misconfigured installations done via auto-installers.
Exploit / POC
Geeklog Multiple Remote File Include Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
Geeklog Multiple Remote File Include Vulnerabilities
Solution:
The vendor indicates that this issue affects only misconfigured installations done via auto-installers.
The vendor released version 1.4.0sr4 to address this issue. Please see the references for more information.
Geeklog Geeklog 1.4.0sr2
Geeklog Geeklog 1.4.0sr3
Geeklog Geeklog 1.4 sr1
Solution:
The vendor indicates that this issue affects only misconfigured installations done via auto-installers.
The vendor released version 1.4.0sr4 to address this issue. Please see the references for more information.
Geeklog Geeklog 1.4.0sr2
-
Geeklog Geeklog 1.4.0sr4
http://www.geeklog.net/filemgmt/visit.php?lid=727
Geeklog Geeklog 1.4.0sr3
-
Geeklog Geeklog 1.4.0sr4
http://www.geeklog.net/filemgmt/visit.php?lid=727
Geeklog Geeklog 1.4 sr1
-
Geeklog Geeklog 1.4.0sr4
http://www.geeklog.net/filemgmt/visit.php?lid=727
References
Geeklog Multiple Remote File Include Vulnerabilities
References:
References:
- GeekLog <= 1.4.0 (_CONF[path]) Remote File Include Vulnerabilities (Kw3[R]Ln)
- Stud.IP Home Page (Stud.IP)
- Geeklog 1.4.0sr4 Advisory (Geeklog)