Agares Media phpAutoVideo Multiple Remote and Local File Include Vulnerabilities
BID:27023
Info
Agares Media phpAutoVideo Multiple Remote and Local File Include Vulnerabilities
| Bugtraq ID: | 27023 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6615 CVE-2007-6614 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 24 2007 12:00AM |
| Updated: | Jul 06 2016 02:17PM |
| Credit: | MhZ91 is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Agares Media phpAutoVideo 2.21 |
| Not Vulnerable: |
Agares Media phpAutoVideo 2.22 |
Discussion
Agares Media phpAutoVideo Multiple Remote and Local File Include Vulnerabilities
Agares Media phpAutoVideo is prone to multiple remote and local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
Exploiting these issues will allow an attacker to access potentially sensitive information and execute arbitrary scripts or PHP code in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.
These issues affect phpAutoVideo 2.21; other versions may also be affected.
Agares Media phpAutoVideo is prone to multiple remote and local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
Exploiting these issues will allow an attacker to access potentially sensitive information and execute arbitrary scripts or PHP code in the context of the webserver process. This may allow the attacker to compromise the application and the underlying computer; other attacks are also possible.
These issues affect phpAutoVideo 2.21; other versions may also be affected.
Exploit / POC
Agares Media phpAutoVideo Multiple Remote and Local File Include Vulnerabilities
Attackers may exploit these issues through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/includes/block.php?selected_provider=[LFI]%00
http://www.example.com/admin/frontpage_right.php?loadadminpage=[Evil_Code]
Attackers may exploit these issues through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/includes/block.php?selected_provider=[LFI]%00
http://www.example.com/admin/frontpage_right.php?loadadminpage=[Evil_Code]
Solution / Fix
Agares Media phpAutoVideo Multiple Remote and Local File Include Vulnerabilities
Solution:
The vendor released phpAutoVideo 2.22 to address this issue. Please see the references for further information.
Agares Media phpAutoVideo 2.21
Solution:
The vendor released phpAutoVideo 2.22 to address this issue. Please see the references for further information.
Agares Media phpAutoVideo 2.21
-
Cuyahoga phpAutoVideo_2.22_UPGRADE_from_2.21.zip
http://updates.agaresmedia.com/phpAutoVideo_2.22_UPGRADE_from_2.21.zip
References
Agares Media phpAutoVideo Multiple Remote and Local File Include Vulnerabilities
References:
References:
- phpAutoVideo 2.22 Patch Released (Agares Media)
- phpAutoVideo Homepage (Agares Media)
- Agares PhpAutoVideo 2.21 Remote/Local File Inclusion Vulnerabilities (milw0rm)