Forum 5 PM.PHP Local File Include Vulnerability
BID:18967
Info
Forum 5 PM.PHP Local File Include Vulnerability
| Bugtraq ID: | 18967 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2006 12:00AM |
| Updated: | Jul 14 2006 12:03AM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
Phorum Phorum 5.1.14 Phorum Phorum 5.1.13 Phorum Phorum 5.0.18 Phorum Phorum 5.0.17 a Phorum Phorum 5.0.16 Phorum Phorum 5.0.14 Phorum Phorum 5.0.13 Phorum Phorum 5.0.12 Phorum Phorum 5.0.11 Phorum Phorum 5.0.10 Phorum Phorum 5.0.9 Phorum Phorum 5.0.7 BETA Phorum Phorum 5.0.3 BETA Phorum Phorum 5.0.15a Phorum Phorum 5.0.14 |
| Not Vulnerable: | |
Discussion
Forum 5 PM.PHP Local File Include Vulnerability
Forum 5 is prone to a local file-include vulnerability.
The application fails to sanitize user input when executing the script. In particular the script fails to check for the presence of a directory-traversal sequence ('../').
A successful exploit may allow unauthorized users to view files and to execute local scripts; other attacks are also possible.
There is no specific affected version information available.
Forum 5 is prone to a local file-include vulnerability.
The application fails to sanitize user input when executing the script. In particular the script fails to check for the presence of a directory-traversal sequence ('../').
A successful exploit may allow unauthorized users to view files and to execute local scripts; other attacks are also possible.
There is no specific affected version information available.
Exploit / POC
Forum 5 PM.PHP Local File Include Vulnerability
Attackers can exploit this issue using a web client.
The following proof-of-concept is available:
http://www.example.com/fm.php?GLOBAL[template]=LFI
Attackers can exploit this issue using a web client.
The following proof-of-concept is available:
http://www.example.com/fm.php?GLOBAL[template]=LFI
Solution / Fix
Forum 5 PM.PHP Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Forum 5 PM.PHP Local File Include Vulnerability
References:
References: