Admin News Tools 'download.php' Remote File Download Vulnerability
BID:43567
Info
Admin News Tools 'download.php' Remote File Download Vulnerability
| Bugtraq ID: | 43567 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-2557 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 15 2009 12:00AM |
| Updated: | Jul 15 2009 12:00AM |
| Credit: | Securitylab.ir |
| Vulnerable: |
Admin News Tools Admin News Tools 2.5 |
| Not Vulnerable: | |
Discussion
Admin News Tools 'download.php' Remote File Download Vulnerability
Admin News Tools is prone to a vulnerability that lets attackers download arbitrary files. The issue occurs because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the application. Information harvested may aid in launching further attacks.
Admin News Tools 2.5 is vulnerable; other versions may also be affected.
Admin News Tools is prone to a vulnerability that lets attackers download arbitrary files. The issue occurs because the application fails to sufficiently sanitize user-supplied input.
Exploiting this issue will allow an attacker to view arbitrary files within the context of the application. Information harvested may aid in launching further attacks.
Admin News Tools 2.5 is vulnerable; other versions may also be affected.
Exploit / POC
Admin News Tools 'download.php' Remote File Download Vulnerability
Attackers can launch attacks through a browser.
The following example URI is available:
http://www.example.com/news/system/download.php?fichier=./../up.php
Attackers can launch attacks through a browser.
The following example URI is available:
http://www.example.com/news/system/download.php?fichier=./../up.php
Solution / Fix
Admin News Tools 'download.php' Remote File Download Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Admin News Tools 'download.php' Remote File Download Vulnerability
References:
References: