NewSolved ABS_Path Parameter Remote File Include Vulnerability
BID:19379
CVE-2006-4059 |Info
NewSolved ABS_Path Parameter Remote File Include Vulnerability
| Bugtraq ID: | 19379 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2006 12:00AM |
| Updated: | Aug 08 2006 03:31AM |
| Credit: | Philipp Niedziela is credited with the discovery of this vulnerability. |
| Vulnerable: |
USolved NEWSolved Lite 1.9.2 |
| Not Vulnerable: |
USolved NEWSolved Lite 1.9.3 |
Discussion
NewSolved ABS_Path Parameter Remote File Include Vulnerability
NEWSolved is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
This issue affects version 1.9.2; earlier versions may also be vulnerable.
NEWSolved is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and to gain access to the underlying system.
This issue affects version 1.9.2; earlier versions may also be vulnerable.
Exploit / POC
NewSolved ABS_Path Parameter Remote File Include Vulnerability
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
Attackers can exploit this issue via a web client.
The following proof-of-concept URI is available:
Solution / Fix
NewSolved ABS_Path Parameter Remote File Include Vulnerability
Solution:
The vendor has released version 1.9.3 to address this issue. Users are advised to contact the vendor for more information.
Solution:
The vendor has released version 1.9.3 to address this issue. Users are advised to contact the vendor for more information.
References
NewSolved ABS_Path Parameter Remote File Include Vulnerability
References:
References:
- NEWSolved Lite v1.9.2 (abs_path) Remote File Inclusion (Philipp Niedziela)
- Usolved Homepage (USolved)
- NEWSolved Lite v1.9.2 (abs_path) Remote File Inclusion (Philipp Niedziela)