LoudBlog 'parse_old.php' Remote File Include Vulnerability
BID:27157
Info
LoudBlog 'parse_old.php' Remote File Include Vulnerability
| Bugtraq ID: | 27157 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0139 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Eugene Minaev discovered this vulnerability. |
| Vulnerable: |
LoudBlog LoudBlog 0.6.1 LoudBlog LoudBlog 0.5 LoudBlog LoudBlog 0.41 LoudBlog LoudBlog 0.4 |
| Not Vulnerable: | |
Discussion
LoudBlog 'parse_old.php' Remote File Include Vulnerability
LoudBlog is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include and execute arbitrary remote file in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
This issue affects LoudBlog 0.6.1 and prior versions.
LoudBlog is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include and execute arbitrary remote file in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
This issue affects LoudBlog 0.6.1 and prior versions.
Exploit / POC
LoudBlog 'parse_old.php' Remote File Include Vulnerability
An attacker can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/loudblog/inc/parse_old.php?template=@phpinfo();@&php_use=1&phpseparator=@&parsedpage=@phpinfo();@
An attacker can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/loudblog/inc/parse_old.php?template=@phpinfo();@&php_use=1&phpseparator=@&parsedpage=@phpinfo();@
Solution / Fix
LoudBlog 'parse_old.php' Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].