Advanced Software Engineering ChartDirector For PHP Information Disclosure Vulnerability
BID:28674
Info
Advanced Software Engineering ChartDirector For PHP Information Disclosure Vulnerability
| Bugtraq ID: | 28674 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1782 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 07 2008 12:00AM |
| Updated: | May 07 2015 05:30PM |
| Credit: | Stack-Terrorist |
| Vulnerable: |
Advanced Software Engineering ChartDirector for PHP 4.1 |
| Not Vulnerable: | |
Discussion
Advanced Software Engineering ChartDirector For PHP Information Disclosure Vulnerability
ChartDirector for PHP is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files from the current directory of the script in the context of the webserver process. This may aid in further attacks.
ChartDirector 4.1 for PHP is vulnerable; other versions may also be affected.
ChartDirector for PHP is prone to an information-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view local files from the current directory of the script in the context of the webserver process. This may aid in further attacks.
ChartDirector 4.1 for PHP is vulnerable; other versions may also be affected.
Exploit / POC
Advanced Software Engineering ChartDirector For PHP Information Disclosure Vulnerability
Attackers can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/chartdirector/phpdemo/viewsource.php?file=viewsource.php
Attackers can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/chartdirector/phpdemo/viewsource.php?file=viewsource.php
Solution / Fix
Advanced Software Engineering ChartDirector For PHP Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Advanced Software Engineering ChartDirector For PHP Information Disclosure Vulnerability
References:
References:
- ChartDirector Homepage (Advanced Software Engineering)