CuteFlow Bin 'login.php' Local File Include Vulnerability
BID:28419
Info
CuteFlow Bin 'login.php' Local File Include Vulnerability
| Bugtraq ID: | 28419 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1493 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 24 2008 12:00AM |
| Updated: | May 07 2015 05:32PM |
| Credit: | KnocKout is credited with the discovery of this vulnerability. |
| Vulnerable: |
Cuteflow Bin Cuteflow Bin 1.5 |
| Not Vulnerable: | |
Discussion
CuteFlow Bin 'login.php' Local File Include Vulnerability
CuteFlow Bin is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
Exploiting these issues may allow an attacker to access potentially sensitive information in the context of the affected application. Information obtained may aid in further attacks.
CuteFlow Bin 1.5.0 is vulnerable to this issue; other versions may also be affected.
CuteFlow Bin is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
Exploiting these issues may allow an attacker to access potentially sensitive information in the context of the affected application. Information obtained may aid in further attacks.
CuteFlow Bin 1.5.0 is vulnerable to this issue; other versions may also be affected.
Exploit / POC
CuteFlow Bin 'login.php' Local File Include Vulnerability
Attackers can exploit this issue via a browser.
The following proof of concept is available:
http://www.example.com/path/login.php?language=[LocalFile]
Attackers can exploit this issue via a browser.
The following proof of concept is available:
http://www.example.com/path/login.php?language=[LocalFile]
Solution / Fix
CuteFlow Bin 'login.php' Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
CuteFlow Bin 'login.php' Local File Include Vulnerability
References:
References:
- Cuteflow Bin Homepage (Cuteflow Bin)