GAMERFUN EXPLORER GF-3XPLORER Local File Include and Cross-Site Scripting Vulnerabilities
BID:26936
Info
GAMERFUN EXPLORER GF-3XPLORER Local File Include and Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 26936 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6475 CVE-2007-6474 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 18 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | MhZ91 is credited with the discovery of these issues. |
| Vulnerable: |
GAMERFUN EXPLORER GF-3XPLORER 2.4 |
| Not Vulnerable: | |
Discussion
GAMERFUN EXPLORER GF-3XPLORER Local File Include and Cross-Site Scripting Vulnerabilities
GAMERFUN EXPLORER GF-3XPLORER is prone to multiple local file-include vulnerabilities and a cross-site scripting vulnerability.
An attacker could exploit these issues to execute local script code in the context of the application and access sensitive data. The attacker may also be able to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
These issues affect GF-3XPLORER 2.4; other versions may also be vulnerable.
GAMERFUN EXPLORER GF-3XPLORER is prone to multiple local file-include vulnerabilities and a cross-site scripting vulnerability.
An attacker could exploit these issues to execute local script code in the context of the application and access sensitive data. The attacker may also be able to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
These issues affect GF-3XPLORER 2.4; other versions may also be vulnerable.
Exploit / POC
GAMERFUN EXPLORER GF-3XPLORER Local File Include and Cross-Site Scripting Vulnerabilities
Attackers can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user to view a maliciously crafted URI.
The following proof-of-concept URIs are available:
For the local file-include issues:
http://www.example.com/updater.php?lang_sel=[LFI]%00
http://www.example.com/thumber.php?lang_sel=[LFI]%00
For the cross-site scripting issue:
http://www.example.com/index_3x.php?newdir=">[XSS]
Attackers can exploit these issues via a browser. To exploit a cross-site scripting vulnerability, the attacker must entice an unsuspecting user to view a maliciously crafted URI.
The following proof-of-concept URIs are available:
For the local file-include issues:
http://www.example.com/updater.php?lang_sel=[LFI]%00
http://www.example.com/thumber.php?lang_sel=[LFI]%00
For the cross-site scripting issue:
http://www.example.com/index_3x.php?newdir=">[XSS]
Solution / Fix
GAMERFUN EXPLORER GF-3XPLORER Local File Include and Cross-Site Scripting Vulnerabilities
Solution:
Reportedly, the vendor released updates addressing many security issues, but Symantec has not verified if the file-include and cross-site scripting issue have been resolved.
Solution:
Reportedly, the vendor released updates addressing many security issues, but Symantec has not verified if the file-include and cross-site scripting issue have been resolved.
References
GAMERFUN EXPLORER GF-3XPLORER Local File Include and Cross-Site Scripting Vulnerabilities
References:
References:
- GF-3XPLORER Homepage (GAMERFUN EXPLORER)