Exponent CMS Index.PHP Local File Include Vulnerability
BID:20111
CVE-2006-4963 |Info
Exponent CMS Index.PHP Local File Include Vulnerability
| Bugtraq ID: | 20111 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 19 2006 12:00AM |
| Updated: | Sep 20 2006 09:51PM |
| Credit: | rgod is credited with the discovery of this vulnerability. |
| Vulnerable: |
Exponent Exponent 0.96.3 |
| Not Vulnerable: | |
Discussion
Exponent CMS Index.PHP Local File Include Vulnerability
Exponent CMS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to inject arbitrary PHP code into the application's temp files and to include and execute arbitrary files from the vulnerable system in the context of the affected application. Other attacks are possible.
This issue affects version 0.96.3 stable; other versions may also be vulnerable.
Exponent CMS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to inject arbitrary PHP code into the application's temp files and to include and execute arbitrary files from the vulnerable system in the context of the affected application. Other attacks are possible.
This issue affects version 0.96.3 stable; other versions may also be vulnerable.
Exploit / POC
Exponent CMS Index.PHP Local File Include Vulnerability
Attackers can exploit this issue via a web client.
The following sample exploit is available:
Attackers can exploit this issue via a web client.
The following sample exploit is available:
Solution / Fix
Exponent CMS Index.PHP Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Exponent CMS Index.PHP Local File Include Vulnerability
References:
References:
- Exponent CMS Homepage (Exponent)