The Gemini Portal 'lang' Parameter Multiple Local File Include Vulnerabilities
BID:31433
Info
The Gemini Portal 'lang' Parameter Multiple Local File Include Vulnerabilities
| Bugtraq ID: | 31433 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-4720 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2008 12:00AM |
| Updated: | May 07 2015 05:23PM |
| Credit: | ZoRLu |
| Vulnerable: |
Arz Development The Gemini Portal 4.7 |
| Not Vulnerable: | |
Discussion
The Gemini Portal 'lang' Parameter Multiple Local File Include Vulnerabilities
The Gemini Portal is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities using directory-traversal strings to execute arbitrary local PHP scripts within the context of the webserver process.
The Gemini Portal 4.7 is vulnerable; other versions may also be affected.
The Gemini Portal is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities using directory-traversal strings to execute arbitrary local PHP scripts within the context of the webserver process.
The Gemini Portal 4.7 is vulnerable; other versions may also be affected.
Exploit / POC
The Gemini Portal 'lang' Parameter Multiple Local File Include Vulnerabilities
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/script_path/gemini/page/forums/bottom.php?lang=ZoRLu.txt?
http://www.example.com/script_path/gemini/page/forums/category.php?lang=ZoRLu.txt?
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/script_path/gemini/page/forums/bottom.php?lang=ZoRLu.txt?
http://www.example.com/script_path/gemini/page/forums/category.php?lang=ZoRLu.txt?
Solution / Fix
The Gemini Portal 'lang' Parameter Multiple Local File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
The Gemini Portal 'lang' Parameter Multiple Local File Include Vulnerabilities
References:
References:
- The Gemini Portal Homepage (Arz Development)