fuzzylime (cms) Multiple Local File Include Vulnerabilities
BID:35541
Info
fuzzylime (cms) Multiple Local File Include Vulnerabilities
| Bugtraq ID: | 35541 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6834 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2008 12:00AM |
| Updated: | Jun 30 2009 11:00PM |
| Credit: | Cod3rZ |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
fuzzylime (cms) Multiple Local File Include Vulnerabilities
'fuzzylime (cms)' is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary local script code. This can allow the attacker to obtain sensitive information that may aid in further attacks.
This issue affects fuzzylime (cms) 3.01 and 3.01a; other versions may also be affected.
'fuzzylime (cms)' is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary local script code. This can allow the attacker to obtain sensitive information that may aid in further attacks.
This issue affects fuzzylime (cms) 3.01 and 3.01a; other versions may also be affected.
Exploit / POC
fuzzylime (cms) Multiple Local File Include Vulnerabilities
Attackers may exploit this vulnerability via a browser.
The following example URIs are available:
http://www.example.com/code/commupdate.php (type=count&s=[file]\0)
http://www.example/code/newsheads.php?heads=../[file]\0
Attackers may exploit this vulnerability via a browser.
The following example URIs are available:
http://www.example.com/code/commupdate.php (type=count&s=[file]\0)
http://www.example/code/newsheads.php?heads=../[file]\0
Solution / Fix
fuzzylime (cms) Multiple Local File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected].
References
fuzzylime (cms) Multiple Local File Include Vulnerabilities
References:
References: