Hedgehog-CMS Local File Include and PHP code Injection Vulnerabilities
BID:33710
Info
Hedgehog-CMS Local File Include and PHP code Injection Vulnerabilities
| Bugtraq ID: | 33710 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 09 2009 12:00AM |
| Updated: | Feb 11 2009 08:18PM |
| Credit: | Osirys |
| Vulnerable: |
Hedgehog-CMS Hedgehog-CMS 1.21 |
| Not Vulnerable: | |
Discussion
Hedgehog-CMS Local File Include and PHP code Injection Vulnerabilities
Hedgehog-CMS is prone to local file-include and PHP code-injection vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to execute arbitrary PHP code or to view and execute arbitrary local files in the context of the webserver process. This may aid in further attacks.
Hedgehog-CMS 1.21 is affected; other versions may also be vulnerable.
Hedgehog-CMS is prone to local file-include and PHP code-injection vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to execute arbitrary PHP code or to view and execute arbitrary local files in the context of the webserver process. This may aid in further attacks.
Hedgehog-CMS 1.21 is affected; other versions may also be vulnerable.
Exploit / POC
Hedgehog-CMS Local File Include and PHP code Injection Vulnerabilities
Attackers can exploit this issue via a browser.
The following example URI and exploit code are available:
http://www.example.com/[path]/includes/footer.php?c_temp_path=[lf]%00
Attackers can exploit this issue via a browser.
The following example URI and exploit code are available:
http://www.example.com/[path]/includes/footer.php?c_temp_path=[lf]%00
Solution / Fix
Hedgehog-CMS Local File Include and PHP code Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Hedgehog-CMS Local File Include and PHP code Injection Vulnerabilities
References:
References:
- Hedgehog-CMS Homepage (Hedgehog-CMS)