Horde Kronolith FBView.PHP Local File Include Vulnerability
BID:21341
Info
Horde Kronolith FBView.PHP Local File Include Vulnerability
| Bugtraq ID: | 21341 |
| Class: | Input Validation Error |
| CVE: |
CVE-2006-6175 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 29 2006 12:00AM |
| Updated: | Jan 17 2007 09:31PM |
| Credit: | iDefense is credited with the discovery of this vulnerability. |
| Vulnerable: |
Horde Project Kronolith 2.1.3 Horde Project Kronolith 2.1.2 Horde Project Kronolith 2.1.1 Horde Project Kronolith 2.1 Horde Project Kronolith 2.0.6 Horde Project Kronolith 2.0.5 Horde Project Kronolith 2.0.4 Horde Project Kronolith 2.0.3 Horde Project Kronolith 2.0.2 Horde Project Kronolith 2.0.1 Gentoo Linux |
| Not Vulnerable: |
Horde Project Kronolith 2.1.4 Horde Project Kronolith 2.0.7 |
Discussion
Horde Kronolith FBView.PHP Local File Include Vulnerability
Kronolith is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an unauthorized remote user to view arbitrary files and execute local scripts in the context of the web server process.
Versions 2.0.1 through 2.1.3 are vulnerable to this issue; other versions may also be affected.
Kronolith is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
Exploiting this issue may allow an unauthorized remote user to view arbitrary files and execute local scripts in the context of the web server process.
Versions 2.0.1 through 2.1.3 are vulnerable to this issue; other versions may also be affected.
Exploit / POC
Horde Kronolith FBView.PHP Local File Include Vulnerability
Attackers can exploit this issue via a web client.
Attackers can exploit this issue via a web client.
Solution / Fix
Horde Kronolith FBView.PHP Local File Include Vulnerability
Solution:
The vendor has released versions 2.0.7 and 2.1.4 to address this issue.
Horde Project Kronolith 2.0.1
Horde Project Kronolith 2.0.2
Horde Project Kronolith 2.0.3
Horde Project Kronolith 2.0.4
Horde Project Kronolith 2.0.5
Horde Project Kronolith 2.0.6
Horde Project Kronolith 2.1
Horde Project Kronolith 2.1.1
Horde Project Kronolith 2.1.2
Horde Project Kronolith 2.1.3
Solution:
The vendor has released versions 2.0.7 and 2.1.4 to address this issue.
Horde Project Kronolith 2.0.1
-
Horde kronolith-h3-2.1.4.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.1.4.tar.gz
Horde Project Kronolith 2.0.2
-
Horde kronolith-h3-2.1.4.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.1.4.tar.gz
Horde Project Kronolith 2.0.3
-
Horde kronolith-h3-2.1.4.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.1.4.tar.gz
Horde Project Kronolith 2.0.4
-
Horde kronolith-h3-2.1.4.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.1.4.tar.gz
Horde Project Kronolith 2.0.5
-
Horde kronolith-h3-2.1.4.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.1.4.tar.gz
Horde Project Kronolith 2.0.6
-
Horde kronolith-h3-2.1.4.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.1.4.tar.gz
Horde Project Kronolith 2.1
-
Horde kronolith-h3-2.1.4.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.1.4.tar.gz
Horde Project Kronolith 2.1.1
-
Horde kronolith-h3-2.1.4.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.1.4.tar.gz
Horde Project Kronolith 2.1.2
-
Horde kronolith-h3-2.1.4.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.1.4.tar.gz
Horde Project Kronolith 2.1.3
-
Horde kronolith-h3-2.1.4.tar.gz
ftp://ftp.horde.org/pub/kronolith/kronolith-h3-2.1.4.tar.gz
References
Horde Kronolith FBView.PHP Local File Include Vulnerability
References:
References:
- Horde Kronolith Arbitrary Local File Inclusion Vulnerability (iDefense)
- Kronolith Homepage (Horde Project)