RETIRED: Mambo LMTG Myhomepage Component Multiple Remote File Include Vulnerabilities
BID:19584
CVE-2006-4264 |Info
RETIRED: Mambo LMTG Myhomepage Component Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 19584 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-4264 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2006 12:00AM |
| Updated: | May 12 2015 07:49PM |
| Credit: | O.U.T.L.A.W has been credited with the discovery of these vulnerabilities. |
| Vulnerable: |
tectonique lmtg_myhomepage 1.2 |
| Not Vulnerable: | |
Discussion
RETIRED: Mambo LMTG Myhomepage Component Multiple Remote File Include Vulnerabilities
The lmtg_myhomepage component for Mambo is prone multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Versions 1.2 and prior are vulnerable to these issues; other versions may also be affected.
This BID has been retired because this issue is not exploitable.
The lmtg_myhomepage component for Mambo is prone multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Versions 1.2 and prior are vulnerable to these issues; other versions may also be affected.
This BID has been retired because this issue is not exploitable.
Exploit / POC
RETIRED: Mambo LMTG Myhomepage Component Multiple Remote File Include Vulnerabilities
Attackers can exploit these issues via a web client.
The following proof-of-concept URIs are available:
Attackers can exploit these issues via a web client.
The following proof-of-concept URIs are available:
Solution / Fix
RETIRED: Mambo LMTG Myhomepage Component Multiple Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Mambo LMTG Myhomepage Component Multiple Remote File Include Vulnerabilities
References:
References: