Smart Publisher '/admin/op/disp.php' Remote Code Execution Vulnerability
BID:27488
Info
Smart Publisher '/admin/op/disp.php' Remote Code Execution Vulnerability
| Bugtraq ID: | 27488 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0503 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 29 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | GoLd_M is credited with discovering this vulnerability. |
| Vulnerable: |
Netwerk Smart Publisher 1.0.1 |
| Not Vulnerable: |
Netwerk Smart Publisher 1.0.2 |
Discussion
Smart Publisher '/admin/op/disp.php' Remote Code Execution Vulnerability
Smart Publisher is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
An attacker can leverage this issue to execute arbitrary PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
This issue affects Smart Publisher 1.0.1; prior versions may also be affected.
Smart Publisher is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
An attacker can leverage this issue to execute arbitrary PHP code on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
This issue affects Smart Publisher 1.0.1; prior versions may also be affected.
Exploit / POC
Smart Publisher '/admin/op/disp.php' Remote Code Execution Vulnerability
Attackers may exploit this issue through a browser.
The following proof-of-concept URI is available:
http://www.example.com/admin/op/disp.php?filedata=cGhwaW5mbygp
Attackers may exploit this issue through a browser.
The following proof-of-concept URI is available:
http://www.example.com/admin/op/disp.php?filedata=cGhwaW5mbygp
Solution / Fix
Smart Publisher '/admin/op/disp.php' Remote Code Execution Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Netwerk Smart Publisher 1.0.1
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Netwerk Smart Publisher 1.0.1
-
Netwerk smart-publisher.1.0.2.zip
http://freshmeat.net/redir/smart-publisher/65026/url_zip/smart-publish er.1.0.2.zip
References
Smart Publisher '/admin/op/disp.php' Remote Code Execution Vulnerability
References:
References:
- Smart Publisher 1.0.2 Release Notes (Netwerk)
- Smart Publisher Homepage (Netwerk)