Xomol CMS 'index.php' Local File Include Vulnerability
BID:29359
Info
Xomol CMS 'index.php' Local File Include Vulnerability
| Bugtraq ID: | 29359 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2483 |
| Remote: | Yes |
| Local: | No |
| Published: | May 25 2008 12:00AM |
| Updated: | May 07 2015 05:28PM |
| Credit: | DNX |
| Vulnerable: |
xomol.net Xomol CMS 1.2 xomol.net Xomol CMS 1 |
| Not Vulnerable: |
xomol.net Xomol CMS 1.5 xomol.net Xomol CMS 1.3 |
Discussion
Xomol CMS 'index.php' Local File Include Vulnerability
Xomol CMS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability using directory-traversal strings to view files and execute local scripts in the context of the webserver process. This may aid in further attacks.
Versions prior to Xomol CMS 1.3 are vulnerable.
Xomol CMS is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability using directory-traversal strings to view files and execute local scripts in the context of the webserver process. This may aid in further attacks.
Versions prior to Xomol CMS 1.3 are vulnerable.
Exploit / POC
Xomol CMS 'index.php' Local File Include Vulnerability
Attackers can exploit this issue using a browser.
The following proof-of-concept URI is available:
http://www.example.com/index.php?op=../../../../../../../../../../etc/passwd%00
Attackers can exploit this issue using a browser.
The following proof-of-concept URI is available:
http://www.example.com/index.php?op=../../../../../../../../../../etc/passwd%00
Solution / Fix
Xomol CMS 'index.php' Local File Include Vulnerability
Solution:
The vendor indicates that this issue has been addressed in Xomol CMS 1.3.
Solution:
The vendor indicates that this issue has been addressed in Xomol CMS 1.3.