Bitweaver 'edit.php' Source Code Information Disclosure Vulnerability
BID:27081
Info
Bitweaver 'edit.php' Source Code Information Disclosure Vulnerability
| Bugtraq ID: | 27081 |
| Class: | Input Validation Error |
| CVE: |
CVE-2007-6651 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 31 2007 12:00AM |
| Updated: | May 07 2015 05:34PM |
| Credit: | AmnPardaz Security Research Team is credited with the discovery of this issue. |
| Vulnerable: |
Bitweaver Bitweaver 2.0 |
| Not Vulnerable: | |
Discussion
Bitweaver 'edit.php' Source Code Information Disclosure Vulnerability
Bitweaver is prone to a vulnerability that allows attackers to access source code because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks.
Bitweaver 2.0 is vulnerable; other versions may also be affected.
Bitweaver is prone to a vulnerability that allows attackers to access source code because the application fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process. Information obtained may aid in further attacks.
Bitweaver 2.0 is vulnerable; other versions may also be affected.
Exploit / POC
Bitweaver 'edit.php' Source Code Information Disclosure Vulnerability
Attackers can exploit this vulnerability with a browser.
The following example URI is available:
http://www.example.com/bitweaver/wiki/edit.php?page=SandBox&suck_url=./../kernel/config_inc.php&do_suck=h
Attackers can exploit this vulnerability with a browser.
The following example URI is available:
http://www.example.com/bitweaver/wiki/edit.php?page=SandBox&suck_url=./../kernel/config_inc.php&do_suck=h
Solution / Fix
Bitweaver 'edit.php' Source Code Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Bitweaver 'edit.php' Source Code Information Disclosure Vulnerability
References:
References: