Fantastico De Luxe 'fantasticopath' Parameter Local File Include Vulnerability
BID:31196
Info
Fantastico De Luxe 'fantasticopath' Parameter Local File Include Vulnerability
| Bugtraq ID: | 31196 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4181 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 14 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | joker_1 |
| Vulnerable: |
Netenberg Fantastico De Luxe 2.10.4 |
| Not Vulnerable: |
Netenberg Fantastico De Luxe 2.10.4 r19 |
Discussion
Fantastico De Luxe 'fantasticopath' Parameter Local File Include Vulnerability
Fantastico De Luxe is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view files and execute local scripts in the context of the webserver process. This may aid in further attacks.
Versions prior to Fantastico De Luxe 2.10.4 r19 are affected.
Fantastico De Luxe is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view files and execute local scripts in the context of the webserver process. This may aid in further attacks.
Versions prior to Fantastico De Luxe 2.10.4 r19 are affected.
Exploit / POC
Fantastico De Luxe 'fantasticopath' Parameter Local File Include Vulnerability
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/frontend/x/fantastico/includes/xml.php?fantasticopath=[LFI]
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/frontend/x/fantastico/includes/xml.php?fantasticopath=[LFI]
Solution / Fix
Fantastico De Luxe 'fantasticopath' Parameter Local File Include Vulnerability
Solution:
The vendor has released fixes. Please see the references for more information.
Solution:
The vendor has released fixes. Please see the references for more information.
References
Fantastico De Luxe 'fantasticopath' Parameter Local File Include Vulnerability
References:
References:
- Fantastico Homepage (Netenberg)
- Fantastico De Luxe 2.10.4 r19 (Netenberg)