Haakon Nilsen SIPS Remote Arbitrary Code Execution Vulnerability
BID:3396
Info
Haakon Nilsen SIPS Remote Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 3396 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2001 12:00AM |
| Updated: | Oct 02 2001 12:00AM |
| Credit: | This vulnerability was submitted to BugTraq on October 2nd, 2001 by atil <[email protected]> and genetics <[email protected]>. |
| Vulnerable: |
Haakon Nilsen SIPS 0.3 |
| Not Vulnerable: | |
Discussion
Haakon Nilsen SIPS Remote Arbitrary Code Execution Vulnerability
SIPS is a weblog and link indexing system used for PHP enabled web servers and is maintained by Haakon Nilsen.
A problem exists in SIPS that will allow a remote attacker to execute arbitrary code on a host running the software(with the privileges of the webserver process). It is possible to supply arbitrary data to the $include variable. This variable is used to specify a file containing PHP code that is to be executed. As a result, the affected script may be redirected to execute arbitrary code located on an external host, as specified by the attacker.
This issue can be exploited if the remote attacker submits a maliciously crafted URL.
SIPS is a weblog and link indexing system used for PHP enabled web servers and is maintained by Haakon Nilsen.
A problem exists in SIPS that will allow a remote attacker to execute arbitrary code on a host running the software(with the privileges of the webserver process). It is possible to supply arbitrary data to the $include variable. This variable is used to specify a file containing PHP code that is to be executed. As a result, the affected script may be redirected to execute arbitrary code located on an external host, as specified by the attacker.
This issue can be exploited if the remote attacker submits a maliciously crafted URL.
Exploit / POC
Haakon Nilsen SIPS Remote Arbitrary Code Execution Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Haakon Nilsen SIPS Remote Arbitrary Code Execution Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Haakon Nilsen SIPS Remote Arbitrary Code Execution Vulnerability
References:
References:
- SIPS Product Information Page on SourceForge (SourceForge)