QuiXplorer 'lang' Parameter Local File Include Vulnerability
BID:37393
Info
QuiXplorer 'lang' Parameter Local File Include Vulnerability
| Bugtraq ID: | 37393 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2009 12:00AM |
| Updated: | Dec 19 2009 12:03AM |
| Credit: | Juan Galiana Lara |
| Vulnerable: |
Soren Eberhardt-Biermann joomlaXplorer 1.6.3 QuiXplore QuiXplore 2.4.1 beta QuiXplore QuiXplore 2.3.1 QuiXplore QuiXplore 2.3 QuiXplore QuiXplore 2.2 QuiXplore QuiXplore 2.1.1 QuiXplore QuiXplore 2.0 |
| Not Vulnerable: | |
Discussion
QuiXplorer 'lang' Parameter Local File Include Vulnerability
QuiXplorer is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
QuiXplorer 2.4.1beta is vulnerable; other versions may also be affected.
QuiXplorer is prone to a local file-include vulnerability because it fails to sufficiently sanitize user-supplied data.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
QuiXplorer 2.4.1beta is vulnerable; other versions may also be affected.
Exploit / POC
QuiXplorer 'lang' Parameter Local File Include Vulnerability
An attacker can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/path/?lang=../path/to/malicious_uploaded_code
An attacker can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/path/?lang=../path/to/malicious_uploaded_code
Solution / Fix
QuiXplorer 'lang' Parameter Local File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of any recent information, please mail us at: [email protected].
References
QuiXplorer 'lang' Parameter Local File Include Vulnerability
References:
References:
- Homepage (QuiXplorer)
- joomlaXplorer Homepage (Soren Eberhardt-Biermann)
- [ISecAuditors Security Advisories] QuiXplorer <=2.4.1beta Remote Code Execution (ISecAuditors Security Advisories
)