TxtBlog 'm' Parameter Local File Include Vulnerability
BID:32498
Info
TxtBlog 'm' Parameter Local File Include Vulnerability
| Bugtraq ID: | 32498 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5639 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 27 2008 12:00AM |
| Updated: | May 07 2015 05:20PM |
| Credit: | CWH Underground |
| Vulnerable: |
TxtBlog TxtBlog 1.0 Alpha |
| Not Vulnerable: | |
Discussion
TxtBlog 'm' Parameter Local File Include Vulnerability
TxtBlog is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary local script code. This can allow the attacker to obtain sensitive information that may aid in further attacks. Other attacks are also possible.
TxtBlog 1.0 Alpha is vulnerable; other versions may also be affected.
TxtBlog is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this issue to execute arbitrary local script code. This can allow the attacker to obtain sensitive information that may aid in further attacks. Other attacks are also possible.
TxtBlog 1.0 Alpha is vulnerable; other versions may also be affected.
Exploit / POC
TxtBlog 'm' Parameter Local File Include Vulnerability
Attackers may exploit this vulnerability via a web browser.
The following example URI is available:
http://www.example.com/[txtblogcms_path]/index.php?y=2005&m=01/../../../../../../../../etc/passwd%00
Attackers may exploit this vulnerability via a web browser.
The following example URI is available:
http://www.example.com/[txtblogcms_path]/index.php?y=2005&m=01/../../../../../../../../etc/passwd%00
Solution / Fix
TxtBlog 'm' Parameter Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected].
References
TxtBlog 'm' Parameter Local File Include Vulnerability
References:
References:
- TxtBlog SourceForge Page (TxtBlog)