RETIRED: clearBudget 'controller.class.php' Remote File Include Vulnerability
BID:42351
Info
RETIRED: clearBudget 'controller.class.php' Remote File Include Vulnerability
| Bugtraq ID: | 42351 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2010 12:00AM |
| Updated: | Aug 11 2010 03:04PM |
| Credit: | Offensive and Red-Stone |
| Vulnerable: |
ClearBudget ClearBudget 0.9.8 |
| Not Vulnerable: | |
Discussion
RETIRED: clearBudget 'controller.class.php' Remote File Include Vulnerability
clearBudget is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
clearBudget version 0.9.8 is vulnerable. Others may also be affected.
This BID is being retired. The issue can not be exploited as described.
clearBudget is prone to a remote file-include vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue may allow an attacker to compromise the application and the underlying system; other attacks are also possible.
clearBudget version 0.9.8 is vulnerable. Others may also be affected.
This BID is being retired. The issue can not be exploited as described.
Exploit / POC
RETIRED: clearBudget 'controller.class.php' Remote File Include Vulnerability
An attacker can exploit this issue via a web client.
The following example URI is available:
http://www.example.com/clearBudget.0.9.8/logic/controller.class.php?actionPath=[file]
An attacker can exploit this issue via a web client.
The following example URI is available:
http://www.example.com/clearBudget.0.9.8/logic/controller.class.php?actionPath=[file]
Solution / Fix
RETIRED: clearBudget 'controller.class.php' Remote File Include Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: clearBudget 'controller.class.php' Remote File Include Vulnerability
References:
References:
- Home page (Fabrice Douteaud)