Hardkap Pritlog 'filename' Parameter File Disclosure Vulnerability
BID:31503
Info
Hardkap Pritlog 'filename' Parameter File Disclosure Vulnerability
| Bugtraq ID: | 31503 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6012 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 30 2008 12:00AM |
| Updated: | May 07 2015 05:22PM |
| Credit: | Pepelux |
| Vulnerable: |
Hardkap Pritlog 0.4 |
| Not Vulnerable: |
Hardkap Pritlog 0.41 |
Discussion
Hardkap Pritlog 'filename' Parameter File Disclosure Vulnerability
Pritlog is prone to a file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability using directory-traversal attacks to view local files in the context of the webserver process. This may aid in further attacks.
Versions up to and including Pritlog 0.4 are vulnerable.
Pritlog is prone to a file-disclosure vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability using directory-traversal attacks to view local files in the context of the webserver process. This may aid in further attacks.
Versions up to and including Pritlog 0.4 are vulnerable.
Exploit / POC
Hardkap Pritlog 'filename' Parameter File Disclosure Vulnerability
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/p/index.php?option=viewEntry&filename=../config.php%00
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/p/index.php?option=viewEntry&filename=../config.php%00
Solution / Fix
Hardkap Pritlog 'filename' Parameter File Disclosure Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Hardkap Pritlog 0.4
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Hardkap Pritlog 0.4
-
Hardkap Pritlog_0.41.zip
http://hardkap.net/pritlog/Pritlog_0.41.zip
References
Hardkap Pritlog 'filename' Parameter File Disclosure Vulnerability
References:
References:
- Pritlog Homepage (Hardkap)
- Pritlog <= 0.4: Remote File Edition Vulnerability (Pepelux
)