RETIRED: Esvon Classifieds Remote Command Execution and Remote File Include Vulnerabilities
BID:42819
Info
RETIRED: Esvon Classifieds Remote Command Execution and Remote File Include Vulnerabilities
| Bugtraq ID: | 42819 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 27 2010 12:00AM |
| Updated: | Sep 20 2010 08:41PM |
| Credit: | Sn!pEr.S!Te Hacker |
| Vulnerable: |
Esvon Esvon Classifieds 4.0 |
| Not Vulnerable: | |
Discussion
RETIRED: Esvon Classifieds Remote Command Execution and Remote File Include Vulnerabilities
Esvon Classifieds is prone to a remote command-execution vulnerability and multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary commands, obtain potentially sensitive information and execute arbitrary script code in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
RETIRED: This BID is retired; following further analysis, these issues are not exploitable as described.
Esvon Classifieds is prone to a remote command-execution vulnerability and multiple remote file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these issues to execute arbitrary commands, obtain potentially sensitive information and execute arbitrary script code in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
RETIRED: This BID is retired; following further analysis, these issues are not exploitable as described.
Exploit / POC
RETIRED: Esvon Classifieds Remote Command Execution and Remote File Include Vulnerabilities
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/inc/pdo.inc.php?sql= [inj3ct0r command]
http://www.example.com/inc/class.phpmailer.php?lang_path=[inj3ct0r RFI]
http://www.example.com/inc/class.phpmailer.php?lang_type=[inj3ct0r RFI]
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/inc/pdo.inc.php?sql= [inj3ct0r command]
http://www.example.com/inc/class.phpmailer.php?lang_path=[inj3ct0r RFI]
http://www.example.com/inc/class.phpmailer.php?lang_type=[inj3ct0r RFI]
Solution / Fix
RETIRED: Esvon Classifieds Remote Command Execution and Remote File Include Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
RETIRED: Esvon Classifieds Remote Command Execution and Remote File Include Vulnerabilities
References:
References:
- Esvon Classifieds Homepage (Esvon)