Photobase 'header.php' Local File Include Vulnerability
BID:33205
Info
Photobase 'header.php' Local File Include Vulnerability
| Bugtraq ID: | 33205 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-5819 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 12 2009 12:00AM |
| Updated: | Jan 27 2009 07:49PM |
| Credit: | Danny Moules |
| Vulnerable: |
X-Interactive Photobase 1.2 |
| Not Vulnerable: | |
Discussion
Photobase 'header.php' Local File Include Vulnerability
Photobase is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view files and execute local scripts in the context of the webserver process. This may aid in further attacks.
The issue affects Photobase 1.2; other versions may be vulnerable as well.
Photobase is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to view files and execute local scripts in the context of the webserver process. This may aid in further attacks.
The issue affects Photobase 1.2; other versions may be vulnerable as well.
Exploit / POC
Photobase 'header.php' Local File Include Vulnerability
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/include/header.php?language=../../../../../../../../../../etc/passwd%00
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/include/header.php?language=../../../../../../../../../../etc/passwd%00
Solution / Fix
Photobase 'header.php' Local File Include Vulnerability
Solution:
Vendor updates are available. Contact the vendor for details.
Solution:
Vendor updates are available. Contact the vendor for details.