SuperMod Multiple Remote File Include Vulnerabilities
BID:20570
Info
SuperMod Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 20570 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 16 2006 12:00AM |
| Updated: | Oct 17 2006 08:54PM |
| Credit: | sZ has been credited with the discovery of this vulnerability. |
| Vulnerable: |
SuperMod SuperMod 3.0 |
| Not Vulnerable: | |
Discussion
SuperMod Multiple Remote File Include Vulnerabilities
SuperMod is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
A successful exploit of these issues allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
SuperMod version 3.0.0 is vulnerable to these issues.
SuperMod is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
A successful exploit of these issues allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
SuperMod version 3.0.0 is vulnerable to these issues.
Exploit / POC
SuperMod Multiple Remote File Include Vulnerabilities
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
SuperMod Multiple Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
SuperMod Multiple Remote File Include Vulnerabilities
References:
References:
- Remote file include vuln found by sZ [oct 09, 2006] (sZ)
- SuperMod Homepage (SuperMod)