phpMyWebmin Remote File Include and Information Disclosure Vulnerabilities
BID:20264
Info
phpMyWebmin Remote File Include and Information Disclosure Vulnerabilities
| Bugtraq ID: | 20264 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 29 2006 12:00AM |
| Updated: | Sep 29 2006 07:35PM |
| Credit: | Kernel-32 discovered these vulnerabilities. |
| Vulnerable: |
phpMyWebmin phpMyWebmin 1.0 |
| Not Vulnerable: | |
Discussion
phpMyWebmin Remote File Include and Information Disclosure Vulnerabilities
phpMyWebmin is affected by a remote file-include and an information-disclosure vulnerability.
An attacker may leverage these issues to execute arbitrary script code on an affected computer with the privileges of the webserver process. This may potentially facilitate unauthorized access.
Note that these issues may also be leveraged to list arbitrary files on an affected computer with the privileges of the webserver. Using this vulnerability, an attacker may be able to employ directory-traversal sequences and NULL characters to access arbitrary system files.
phpMyWebmin version 1.0 is known to be vulnerable. Other versions may be affected as well.
phpMyWebmin is affected by a remote file-include and an information-disclosure vulnerability.
An attacker may leverage these issues to execute arbitrary script code on an affected computer with the privileges of the webserver process. This may potentially facilitate unauthorized access.
Note that these issues may also be leveraged to list arbitrary files on an affected computer with the privileges of the webserver. Using this vulnerability, an attacker may be able to employ directory-traversal sequences and NULL characters to access arbitrary system files.
phpMyWebmin version 1.0 is known to be vulnerable. Other versions may be affected as well.
Exploit / POC
phpMyWebmin Remote File Include and Information Disclosure Vulnerabilities
Attackers can exploit these issues via a web client.
The following proof-of-concept URIs are available:
http://www.example.com/path/window.php?target=/etc
http://www.example.com/path/home.php?target=/home
http://www.example.com/path/window.php?action=Shell.php
Attackers can exploit these issues via a web client.
The following proof-of-concept URIs are available:
http://www.example.com/path/window.php?target=/etc
http://www.example.com/path/home.php?target=/home
http://www.example.com/path/window.php?action=Shell.php
Solution / Fix
phpMyWebmin Remote File Include and Information Disclosure Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
phpMyWebmin Remote File Include and Information Disclosure Vulnerabilities
References:
References:
- PHP MyWebMin 1.0 Remote File Include (Kernel-32)
- phpMyWebmin Home Page (Josh Muheim)