Achievo 'debugger.php' Remote File Include Vulnerability
BID:36822
Info
Achievo 'debugger.php' Remote File Include Vulnerability
| Bugtraq ID: | 36822 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 11 2009 12:00AM |
| Updated: | Oct 27 2009 07:28PM |
| Credit: | M3NW5 |
| Vulnerable: |
Achievo Achievo 1.3.4 Achievo Achievo 1.3.2 Achievo Achievo 1.2.1 Achievo Achievo 1.1 Achievo Achievo 1.2 |
| Not Vulnerable: |
Achievo Achievo 1.4 |
Discussion
Achievo 'debugger.php' Remote File Include Vulnerability
Achievo is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the computer; other attacks are also possible.
Versions prior to Achievo 1.4.0 are vulnerable.
Achievo is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the computer; other attacks are also possible.
Versions prior to Achievo 1.4.0 are vulnerable.
Exploit / POC
Achievo 'debugger.php' Remote File Include Vulnerability
An attacker can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/path/debugger.php?config_atkroot=<deviL>
An attacker can exploit this issue via a browser.
The following proof-of-concept URI is available:
http://www.example.com/path/debugger.php?config_atkroot=<deviL>
Solution / Fix
Achievo 'debugger.php' Remote File Include Vulnerability
Solution:
The vendor has released an update. Please see the references for details.
Solution:
The vendor has released an update. Please see the references for details.
References
Achievo 'debugger.php' Remote File Include Vulnerability
References:
References:
- Achievo 1.4.0 Release Notes (Achievo)
- Achievo Homepage (Achievo)